CVE-2026-10540: Bmc Control-M/enterprise Manager

Medium severity, CVSS 5.6. EPSS: 0.1% chance of exploitation in the next 30 days.

The Control-M/Enterprise Manager uses weak protections for stored hashes of account passwords, potentially allowing offline password recovery attacks if credential data is obtained by an attacker. This vulnerability affects Control-M/Enterprise Manager unsupported versions 9.0.20.x and potentially earlier unsupported versions

Affected products

  • Bmc Control-M/enterprise Manager: from 9.0.20, before 9.0.21 (fixed in 9.0.21)

Published 2026-07-01. Last modified 2026-07-01.