
CVE-2026-23782 An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allows unauthenticated users to obtain both an API identifier and its c… https://www.cve.org/CVERecord?id=CVE-2026-23782
Post summary
CVE-2026-23782 exposes unauthenticated access to an API endpoint in BMC Control‑M/MFT 9.0.20‑9.0.22, allowing retrieval of an API identifier and likely additional data, with no PoC, exploit, or patch information provided.


