Unauthenticated SQL Injection and RCE in mJobTime
mJobTime builds through 15.7.3.32 contain an unauthenticated SQL injection vulnerability in Login.aspx allowing attackers to execute arbitrary commands as LocalSystem via xp_cmdshell.
CVE search metadata
CVE search record: CVE-2026-9209. Severity: critical. CVSS: 9.8. KEV: no. Product: mJobTime (<= 15.7.3.32). Brief: Unauthenticated SQL Injection and RCE in mJobTime. Brief link: https://feed.craftedsignal.io/briefs/2026-10-mjobtime-sqli/
mJobTime builds through 15.7.3.32 are vulnerable to a critical unauthenticated SQL injection vulnerability located within the Login.aspx administrative panel. The vulnerability stems from improper input validation in the 'runQueryButton' postback and 'exportSqlQuery_Server' PageMethod, which allow unauthenticated users to execute arbitrary SQL commands against the backend Sybase SQL Anywhere database. Crucially, these queries are executed with DBA or sysadmin-level database privileges.
The application relies on client-side 'sessionStorage' flags for authentication, which can be easily bypassed by an attacker submitting a specifically crafted HTTP request. By leveraging the database's administrative privileges, an attacker can invoke powerful stored procedures such as 'xp_cmdshell' to execute arbitrary operating system commands. This flaw permits complete system compromise, enabling the attacker to run code with the privileges of the database service, typically LocalSystem, with a single unauthenticated HTTP request. Organizations using mJobTime are at high risk of total system takeover and data exfiltration.
Attack Chain
- Attacker identifies a target instance of mJobTime running a vulnerable build (<= 15.7.3.32).
- Attacker crafts a malicious HTTP POST request targeting the /Login.aspx page.
- Attacker targets the 'runQueryButton' postback or 'exportSqlQuery_Server' PageMethod.
- Attacker inserts a payload designed to bypass client-side authentication checks.
- Attacker injects a malicious SQL query containing the 'xp_cmdshell' stored procedure.
- The database executes the injected SQL command with DBA/sysadmin privileges.
- The 'xp_cmdshell' command executes as the LocalSystem user on the underlying Windows host.
- Attacker gains full remote code execution, enabling persistence or further exfiltration.
Impact
Successful exploitation leads to unauthenticated remote code execution with LocalSystem privileges on the server hosting the mJobTime application. This allows attackers to install persistent backdoors, exfiltrate sensitive payroll and personnel data, move laterally within the network, or deploy ransomware. As the application is often used for workforce management, the impact of a breach includes potential exposure of extensive PII and payroll information for all company employees.
Recommendation
- Patch mJobTime to a version beyond 15.7.3.32 immediately to address the vulnerability in Login.aspx.
- Implement strict network segmentation to ensure the mJobTime web server is not reachable from the public internet.
- Disable 'xp_cmdshell' and similar extended stored procedures within the Sybase SQL Anywhere configuration if they are not required for business operations.
- Monitor web server logs for suspicious POST requests to 'Login.aspx' containing SQL-specific keywords like 'xp_cmdshell' or 'xp_read_file'.
Immediate actions
Block external access to /Login.aspx on mJobTime servers
Mitigations
Upgrade mJobTime to version 15.7.3.33 or later
CVE-2026-9209
Detection coverage 1
Detects CVE-2026-9209 Exploitation - SQL Injection Attempt in mJobTime
criticalDetects unauthenticated POST requests to Login.aspx attempting to invoke xp_cmdshell via the vulnerable runQueryButton or exportSqlQuery_Server methods.
Detection queries are available on the platform. Get full rules →