CVE-2026-10539: Unauthenticated command injection in Control-M/Server communication command
A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain conditions, this issue may allow an unauthenticated attacker to execute unauthorized commands on the affected server, potentially leading to compromise of the server.
This vulnerability affects Control-M/Server versions 9.0.20.x to 9.0.21.200 (included) and potentially earlier unsupported versions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10539?
CVE-2026-10539 has a critical severity rating of 9.
What impact does CVE-2026-10539 have?
CVE-2026-10539 allows an unauthenticated attacker to execute unauthorized commands, potentially compromising the server.
How do I fix CVE-2026-10539?
To remediate CVE-2026-10539, apply the latest patches or updates provided by BMC for Control-M/Server.
Is CVE-2026-10539 exploitable remotely?
Yes, CVE-2026-10539 is exploitable remotely, as it allows unauthenticated access.
What versions of BMC Control-M/Server are affected by CVE-2026-10539?
CVE-2026-10539 affects specific versions of BMC Control-M/Server that lack proper input filtering.