CVE-2026-23782: Bmc Control-M/managed File Transfer

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allows unauthenticated users to obtain both an API identifier and its corresponding secret value. With these exposed secrets, an attacker could invoke privileged API operations, potentially leading to unauthorized access.

Affected products

  • Bmc Control-M/managed File Transfer: from 9.0.20, up to and including 9.0.22

Published 2026-04-10. Last modified 2026-06-17.