7.5
CVE-2026-23782
- EPSS 0.27%
- Veröffentlicht 10.04.2026 00:00:00
- Zuletzt bearbeitet 27.04.2026 19:11:46
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allows unauthenticated users to obtain both an API identifier and its corresponding secret value. With these exposed secrets, an attacker could invoke privileged API operations, potentially leading to unauthorized access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bmc ≫ Control-m/managed File Transfer Version >= 9.0.20 <= 9.0.22
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.27% | 0.187 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
https://www.bmc.com/support/resources/issue-defect-management.html
https://docs.bmc.com/xwiki/bin/view/Control-M-Orchestration/Control-M/ctm9021/Patches/Control-M-Server-PACTV-9-0-21-308/?srid=ab0apVT3