Junglewise Threat Intelligence

CVE-2026-10538: BMC Control-M improper deserialization in messaging consumer

CVE-2026-10538 · Severity: high · CVSS 8 · Published 2026-07-01

Executive brief

BMC Control-M, a platform used for automating complex business workflows and job scheduling, contains a security flaw in its messaging component. An authenticated user could send specially crafted data to the server, causing it to process malicious commands. This could lead to unauthorized access to sensitive data, service disruptions, or full control over the affected server.

Technical details

This vulnerability is classified as CWE-502 (Deserialization of Untrusted Data) within the messaging consumer functionality of BMC Control-M/Server and Enterprise Manager. The root cause is a failure to restrict allowed object types during the deserialization of user-provided data. An authenticated attacker with network access to the messaging service can exploit this by sending crafted serialized objects. Successful exploitation could allow the attacker to trigger unintended server-side behavior, including arbitrary code execution. The issue affects versions 9.0.20.x and earlier, which are currently out of support; users are advised to upgrade to version 9.0.21 or later.

Affected products

  • BMC Software Control-M/Enterprise Manager 9.0.20.x and earlier
  • BMC Software Control-M/Server for UNIX and Microsoft Windows 9.0.20.x and earlier

Timeline

  • 2026-07-01: advisory: NVD publication date
  • 2026-07-01: disclosed: BMC Software knowledge article published

References

Related threats