CVE-2026-10540: Weak password hash protection in Control-M/Entreprise Manager
The Control-M/Enterprise Manager uses weak protections for stored hashes of account passwords, potentially allowing offline password recovery attacks if credential data is obtained by an attacker. This vulnerability affects Control-M/Enterprise Manager unsupported versions 9.0.20.x and potentially earlier unsupported versions
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10540?
The severity of CVE-2026-10540 is classified as medium, with a score of 5.6.
How do I fix CVE-2026-10540?
To fix CVE-2026-10540, upgrade to a supported version of BMC Control-M/Enterprise Manager that addresses this vulnerability.
What systems are affected by CVE-2026-10540?
CVE-2026-10540 affects unsupported versions of BMC Control-M/Enterprise Manager, specifically version 9.0.20.x.
What risks are associated with CVE-2026-10540?
CVE-2026-10540 presents risks of offline password recovery attacks if credential data is compromised.
Is there a workaround for CVE-2026-10540?
Currently, there are no documented workarounds for CVE-2026-10540; upgrading to a supported version is the recommended action.