Executive brief
BMC Control-M/MFT is a managed file transfer solution used to automate and secure data movement across corporate networks. A security flaw in its administrative debug interface allows an authorized user to run unauthorized database commands. This could lead to the theft of sensitive data, unauthorized modification of files, or a complete takeover of the affected server.
Technical details
A SQL injection vulnerability exists in the debug interface of the BMC Control-M/MFT API. The flaw is caused by improper input validation and unsafe dynamic SQL handling within the MFT component. An authenticated attacker with network access to the API can exploit this by injecting malicious SQL queries. Successful exploitation allows for arbitrary file read and write operations on the underlying system, which can be further leveraged to achieve remote code execution (RCE). The issue affects versions 9.0.20 through 9.0.22 and is addressed in patch PAAFP.9.0.22.025.
Affected products
- BMC Control-M/Managed File Transfer (MFT) 9.0.20 through 9.0.22
Timeline
- 2026-04-10: disclosed
- 2026-04-10: advisory
- 2026-04-27: patched: NVD updated with patch references