9.8
CVE-2026-23781
- EPSS 0.28%
- Veröffentlicht 10.04.2026 00:00:00
- Zuletzt bearbeitet 27.04.2026 19:11:38
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of default debug user credentials is hardcoded in cleartext within the application package. If left unchanged, these credentials can be easily obtained and may allow unauthorized access to the MFT API debug interface.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bmc ≫ Control-m/managed File Transfer Version >= 9.0.20 <= 9.0.22
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.28% | 0.199 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-798 Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
https://www.bmc.com/support/resources/issue-defect-management.html
https://docs.bmc.com/xwiki/bin/view/Control-M-Orchestration/Control-M/ctm9022/Patches/Control-M-MFT-PAAFP-9-0-22-025/