mJobTime, a workforce management platform used in construction and field services, ships a login page that accepts and executes arbitrary SQL from unauthenticated users. The database connection runs with administrative privileges, which gives an attacker a direct path from a single HTTP request to full remote code execution on the host operating system. The vulnerability exists in product-shipped code and affects every default deployment.

Details here are intentionally sparse and vague.

This vulnerability was assigned CVE-2026-9209. It was handled under coordinated disclosure under a 120-day timeline. At time of publication, no effective vendor fix is available.

Key Takeaways

  • mJobTime's Login.aspx page exposes server-side handlers that execute caller-supplied SQL without authentication. A single POST request is sufficient to run arbitrary queries as a database administrator.
  • The database connection operates with sysadmin-level privileges, giving access to OS command execution primitives (xp_cmdshell on SQL Server, equivalent on Sybase SQL Anywhere).
  • No cookie, ViewState token, anti-forgery token, or authorization header is required.
  • The vulnerability was confirmed against build 15.7.1 and remains exploitable on build 15.7.3.32.

How Does the Vulnerability Work?

Login.aspx includes an embedded administrative panel with a SQL query text area and execution controls. The application renders this panel to all visitors and performs no server-side authentication or authorization on the handlers that process submitted queries.

Two entry points exist:

  1. [REDACTED] PageMethod - Accepts a JSON POST body containing a field. The server executes the query against the backing database and writes the results to a server-side location.
  2. [REDACTED] postback - A standard ASP.NET form postback that executes the SQL from a field and renders results into a popup page.

The only access control is a client-side JavaScript flag (sessionStorage('config_auth')) that toggles CSS visibility on the admin panel (unenforced by the server).

Proof of Concept

An unauthenticated request executes caller-supplied SQL against the backing database:

curl -sk -X POST <https://TARGET/Login.aspx/[REDACTED]> \
---snip---

A successful request returns HTTP 200, and query results are made retrievable by the caller. Running SELECT @@version returns the database engine version; a privilege check confirms the connection's role:

login_name,is_sysadmin
"dba","1"

The connection runs as a sysadmin login. On SQL Server, this level of access reaches xp_cmdshell, which executes operating system commands as the SQL Server service account.

Root Cause

A handler and the administrative PageMethods in Login.aspx contain no User.Identity.IsAuthenticated check, no role validation, and no anti-forgery token requirement. The database connection authenticates as a database administrator with sysadmin privileges. These appear to be product defaults, not deployment misconfigurations.

Remediation

No effective vendor fix is currently available. mJobTime has stated the issue is resolved in build 15.7.3. That build remains exploitable without authentication. Until a corrected build is confirmed, an upgrade is not a remediation, and the following mitigations are the available protection:

  1. Restrict network access to the mJobTime web tier to authorized users only (VPN, IP allowlist, or reverse proxy with authentication).
  2. If possible, disable or remove the handlers at the IIS level.
  3. Reconfigure the database connection to use a least-privileged account instead of a sysadmin login.

Organizations running mJobTime should contact the vendor to confirm affected status and to track a genuinely corrected release.

Disclosure Timeline

Date

Event

2026-05

Vulnerability reported to the vendor under coordinated disclosure.

2026-05

Vendor responded and asserted the issue was addressed in newer releases.

2026-05

Sprocket confirmed the finding was distinct from prior reports and reproduced it against the current shipping build.

2026-05

A third-party CNA was engaged to coordinate disclosure under a 120-day timeline.

2026-06 – 2026-09

The coordinator worked with the vendor toward remediation.

2026-09

Sprocket verified the vendor's claimed fix against a current build; the issue remained exploitable without authentication.

2026-09

The coordinated-disclosure deadline elapsed without an effective fix.

2026-10

Public disclosure.

Related Vulnerabilities

CVE-2025-51683, reported by a separate researcher, documents a distinct SQL injection in mJobTime's Default.aspx/update_profile_Server endpoint. That finding affects a different handler but reflects the same underlying pattern: unauthenticated PageMethods that pass user input directly to SQL execution.

Sprocket Security discovers vulnerabilities like this through continuous penetration testing, where persistent access to a client's environment allows the depth of analysis that point-in-time assessments often miss. For more on Sprocket's approach, visit sprocketsecurity.com.