← Back to CVE search

CVE-2026-23780

BMC Control-M/MFT

Description

An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API-s debug interface allows an authenticated attacker to inject malicious queries due to improper input validation and unsafe dynamic SQL handling. Successful exploitation can enable arbitrary file read/write operations and potentially lead to remote code execution.

CVSS 8.8EPSS 0.40099999999999997%Risk 0.91
View source
Published
2026-04-10 15:16:23
Affected versions
<9.0.23
Type
Installed app
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H