CVE-2026-23782Disclosure(bmc / control-m\/managed_file_transfer)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allows unauthenticated users to obtain both an API identifier and its corresponding secret value. With these exposed secrets, an attacker could invoke privileged API operations, potentially leading to unauthorized access.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • control-m\/managed_file_transfer

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-04-11)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
control-m\/managed_file_transfer

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-10: 1Mentions · 2026-04-11: 2Technical Details · 2026-04-11: 204-1004-11
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-101
General1
2026-04-112
Disclosure2
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-23782 An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allows unauthenticated users to obtain both an API identifier and its c… https://www.cve.org/CVERecord?id=CVE-2026-23782

    Post summary

    CVE-2026-23782 exposes unauthenticated access to an API endpoint in BMC Control‑M/MFT 9.0.20‑9.0.22, allowing retrieval of an API identifier and likely additional data, with no PoC, exploit, or patch information provided.

    00010187
    57.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-23782 An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allows unauthenticated users to obtain both an API identifier and its c… https://www.cve.org/CVERecord?id=CVE-2026-23782 ----- Traducción: Se detectó un prob… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-23782, a vulnerability in BMC Control‑M/MFT 9.0.20‑9.0.22 that permits unauthenticated API access to sensitive identifiers. No PoC, exploit, patch, or active exploitation details are provided.

    0000032
    71 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-23782 Unauthenticated API Secret Exposure in BMC Control-M/MFT 9.0.20-9.0.22 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23782

    Post summary

    The post merely announces CVE‑2026‑23782 and links to a vulnerability detail page, with no additional technical context, PoC, or exploitation information.

    0000041
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbmccontrol-m\/managed_file_transfer---

Explore more