top of page
perceptive_background_267k.jpg

A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain conditions, this issue may allow an unauthe…

Published:

30 juni 2026 om 22:00:00

Alert date:

1 juli 2026 om 09:01:54

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Zero-Day Vulnerabilities

A vulnerability in BMC Control-M/Server allows unauthenticated attackers to execute unauthorized commands due to insufficient input filtering or sanitization in a communication command. The flaw exists in versions 9.0.20.x through 9.0.21.200 and potentially earlier unsupported versions. Successful exploitation could lead to full server compromise. No authentication is required to exploit this vulnerability, significantly raising its severity. The vulnerability was published via NVD and BMC has issued a knowledge article with remediation guidance.

Technical details

Mitigation steps:

Affected products:

BMC Control-M/Server 9.0.20.x
BMC Control-M/Server 9.0.21.200

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page