Junglewise Threat Intelligence

CVE-2026-23782: BMC Control-M/MFT information disclosure in API management endpoint

CVE-2026-23782 · Severity: high · CVSS 7.5 · Published 2026-04-10

Technologies: Bmc Managed File Transfer, Bmc Control-M\. Vendors: Bmc.

Executive brief

BMC Control-M/MFT, a platform used for managing enterprise file transfers, contains a security flaw in its API management interface. An unauthenticated attacker can access a specific endpoint to retrieve sensitive API credentials, including identifiers and secret keys. These stolen credentials can be used to perform administrative or privileged actions, potentially leading to unauthorized data access or disruption of file transfer operations.

Technical details

An information disclosure vulnerability exists in the BMC Control-M/MFT API management endpoint. The flaw allows a remote, unauthenticated attacker to query a specific endpoint and receive both an API identifier and its corresponding secret value in plain text. This is classified as improper access control (CWE-284). With these credentials, the attacker can authenticate as a privileged user to the Control-M Automation API, enabling them to invoke administrative operations. BMC has released patch PACTV.9.0.21.308 for Control-M/Server to address this and related issues.

Affected products

  • BMC Control-M/Managed File Transfer (MFT) 9.0.20 through 9.0.22

Timeline

  • 2026-04-10: advisory: Initial CVE publication
  • 2026-04-10: disclosed
  • 2026-04-27: patched: NVD updated with patch information and CPEs

References

Related threats