CVE-2026-23780: SQL Injection
An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API's debug interface allows an authenticated attacker to inject malicious queries due to improper input validation and unsafe dynamic SQL handling. Successful exploitation can enable arbitrary file read/write operations and potentially lead to remote code execution.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23780?
CVE-2026-23780 is rated as a high severity vulnerability due to its potential for SQL injection exploits.
How do I fix CVE-2026-23780?
To fix CVE-2026-23780, upgrade BMC Control-M/MFT to version 9.0.23 or later where the vulnerability is addressed.
Who is affected by CVE-2026-23780?
CVE-2026-23780 impacts users of BMC Control-M/MFT versions 9.0.20 to 9.0.22.
What kind of attacks can be executed due to CVE-2026-23780?
CVE-2026-23780 allows authenticated attackers to perform SQL injection attacks through the MFT API's debug interface.
Is authentication required to exploit CVE-2026-23780?
Yes, exploiting CVE-2026-23780 requires the attacker to be authenticated to the system.