Junglewise Threat Intelligence

CVE-2026-10539: BMC Control-M/Server command injection in communication command

CVE-2026-10539 · Severity: critical · CVSS 9 · Published 2026-07-01

Vendors: Bmc.

Executive brief

BMC Control-M/Server, a tool used to manage and automate complex business workflows, contains a security flaw in how it handles communication commands. An unauthenticated attacker could exploit this to run unauthorized commands on the server, potentially leading to a full system takeover. This could result in significant operational disruption and the exposure of sensitive business data.

Technical details

This vulnerability is classified as an authentication bypass (CWE-305) leading to remote command injection. The root cause is a failure to sufficiently filter or sanitize user-supplied input within a Control-M/Server communication command. An unauthenticated attacker can exploit this over the network to execute unauthorized commands on the affected server. The issue affects Control-M/Server versions 9.0.20.x through 9.0.21.200. Users are advised to upgrade to version 9.0.21.300 or higher to remediate the vulnerability.

Affected products

  • BMC Control-M/Server for UNIX and Microsoft Windows 9.0.20.x to 9.0.21.200

Timeline

  • 2026-07-01: advisory: Initial advisory published by BMC and NVD
  • 2026-07-01: patched: Fix released in version 9.0.21.300

References