Executive brief
BMC Control-M/Server, a tool used to manage and automate complex business workflows, contains a security flaw in how it handles communication commands. An unauthenticated attacker could exploit this to run unauthorized commands on the server, potentially leading to a full system takeover. This could result in significant operational disruption and the exposure of sensitive business data.
Technical details
This vulnerability is classified as an authentication bypass (CWE-305) leading to remote command injection. The root cause is a failure to sufficiently filter or sanitize user-supplied input within a Control-M/Server communication command. An unauthenticated attacker can exploit this over the network to execute unauthorized commands on the affected server. The issue affects Control-M/Server versions 9.0.20.x through 9.0.21.200. Users are advised to upgrade to version 9.0.21.300 or higher to remediate the vulnerability.
Affected products
- BMC Control-M/Server for UNIX and Microsoft Windows 9.0.20.x to 9.0.21.200
Timeline
- 2026-07-01: advisory: Initial advisory published by BMC and NVD
- 2026-07-01: patched: Fix released in version 9.0.21.300