Executive brief
BMC Control-M/MFT, a platform used for managing enterprise file transfers, contains a security flaw in its API management interface. An unauthenticated attacker can access a specific endpoint to retrieve sensitive API credentials, including identifiers and secret keys. These stolen credentials can be used to perform administrative or privileged actions, potentially leading to unauthorized data access or disruption of file transfer operations.
Technical details
An information disclosure vulnerability exists in the BMC Control-M/MFT API management endpoint. The flaw allows a remote, unauthenticated attacker to query a specific endpoint and receive both an API identifier and its corresponding secret value in plain text. This is classified as improper access control (CWE-284). With these credentials, the attacker can authenticate as a privileged user to the Control-M Automation API, enabling them to invoke administrative operations. BMC has released patch PACTV.9.0.21.308 for Control-M/Server to address this and related issues.
Affected products
- BMC Control-M/Managed File Transfer (MFT) 9.0.20 through 9.0.22
Timeline
- 2026-04-10: advisory: Initial CVE publication
- 2026-04-10: disclosed
- 2026-04-27: patched: NVD updated with patch information and CPEs