Junglewise Threat Intelligence

CVE-2026-10540: BMC Control-M/Enterprise Manager weak password hashing

CVE-2026-10540 · Severity: medium · CVSS 5.6 · Published 2026-07-01

Vendors: Bmc.

Executive brief

BMC Control-M/Enterprise Manager, a workflow orchestration platform, uses an outdated and weak method for securing user passwords. If an attacker gains access to the system's internal database, they could more easily crack these passwords offline to gain unauthorized access to accounts. This issue primarily affects older, unsupported versions of the software, and upgrading to a modern version resolves the risk.

Technical details

The vulnerability is classified as a Use of Weak Hash (CWE-328) within the BMC Control-M/Enterprise Manager credential storage mechanism. The root cause is the use of an insecure hashing algorithm that does not provide sufficient computational resistance against brute-force or rainbow table attacks. An attacker who has already obtained local access or high-privileged access (PR:H) to the underlying database or configuration files can extract these hashes and perform offline password recovery. This vulnerability affects unsupported versions 9.0.20.x and earlier; it is addressed in version 9.0.21 and later.

Affected products

  • BMC Control-M/Enterprise Manager 9.0.20.x and earlier unsupported versions

Timeline

  • 2026-07-01: disclosed
  • 2026-07-01: advisory

References

Related threats