Back

HIGH

An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22

Published Apr 10, 2026

Description

An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API's debug interface allows an authenticated attacker to inject malicious queries due to improper input validation and unsafe dynamic SQL handling. Successful exploitation can enable arbitrary file read/write operations and potentially lead to remote code execution.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Apr 10, 2026
Updated Apr 14, 2026
Reserved Jan 16, 2026

CISA Vulnrichment

Updated Apr 14, 2026

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner mitre
Published Apr 10, 2026
Updated Apr 14, 2026

GitHub

No data