API Management Vulnerability in BMC Control-M/MFT Products
CVE-2026-23782

7.5HIGH

Key Information:

Vendor

BMC

Vendor
CVE Published:
10 April 2026

What is CVE-2026-23782?

A significant vulnerability has been identified in BMC Control-M/MFT versions 9.0.20 through 9.0.22. This issue exists within an API management endpoint that allows unauthenticated individuals to retrieve sensitive API identifiers along with their corresponding secret values. The exposure of these secrets enables malicious actors to potentially carry out privileged API actions, resulting in unauthorized access to the system. It is crucial for organizations utilizing these affected versions to implement security measures promptly to mitigate any risks associated with this vulnerability.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.