PT-2026-31922 · Bmc · Bmc Control-M/Mft
Published
2026-04-10
·
Updated
2026-04-10
·
CVE-2026-23782
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
BMC Control-M/MFT versions 9.0.20 through 9.0.22
Description
An API management endpoint allows unauthenticated users to obtain an API identifier and its corresponding secret value. An attacker could use these exposed secrets to invoke privileged API operations, potentially leading to unauthorized access.
Recommendations
Update to a version later than 9.0.22.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bmc Control-M/Mft