Executive brief
BMC Control-M/MFT, a managed file transfer solution used to automate and secure business data movements, contains hardcoded administrative credentials. An attacker can use these credentials to access a debug interface, potentially allowing them to view sensitive data or interfere with file transfer operations. This could lead to unauthorized access to corporate data and disruption of automated business workflows.
Technical details
A Use of Hard-coded Credentials (CWE-798) vulnerability exists in BMC Control-M/MFT versions 9.0.20 through 9.0.22. The application package includes a set of default debug user credentials stored in cleartext. A remote, unauthenticated attacker can obtain these credentials from the application package and use them to access the MFT API debug interface. Successful exploitation provides unauthorized access to sensitive diagnostic functions and potentially the underlying data handled by the MFT Hub. BMC has released patch PAAFP.9.0.22.025 to address this issue.
Affected products
- BMC Control-M/Managed File Transfer (MFT) 9.0.20 through 9.0.22
Timeline
- 2026-04-10: disclosed: Initial CVE publication
- 2026-04-10: advisory: Vendor advisory released
- 2026-04-27: patched: NVD updated with patch information and CPEs