CVE-2026-23782: High severity BMC Control-M/MFT vulnerability
An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allows unauthenticated users to obtain both an API identifier and its corresponding secret value. With these exposed secrets, an attacker could invoke privileged API operations, potentially leading to unauthorized access.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23782?
CVE-2026-23782 is classified as a high severity vulnerability due to the potential for unauthorized access to privileged API operations.
How do I fix CVE-2026-23782?
To address CVE-2026-23782, apply the latest security patches provided by BMC for Control-M/MFT versions 9.0.20 through 9.0.22.
What systems are affected by CVE-2026-23782?
CVE-2026-23782 affects BMC Control-M/MFT versions 9.0.20, 9.0.21, and 9.0.22.
What type of vulnerability is CVE-2026-23782?
CVE-2026-23782 is an API security vulnerability that allows unauthenticated users to access sensitive API identifiers and secrets.
What could an attacker do with CVE-2026-23782?
An attacker exploiting CVE-2026-23782 could invoke privileged API operations, potentially leading to unauthorized actions within the affected system.