CVE-2026-10539
Ein Steuerungsbefehl für die Kommunikation zwischen Control-M/Server filtert oder bereinigt Benutzereingaben nicht ausreichend (CVE-2026-10539)
Beschreibung
Ein Steuerungsbefehl für die Kommunikation zwischen Control-M/Server filtert oder bereinigt Benutzereingaben nicht ausreichend. Unter bestimmten Bedingungen könnte dieses Problem es einem unauthentifizierten Angreifer ermöglichen, unbefugte Befehle auf dem betroffenen Server auszuführen und möglicherweise zu dessen Kompromittierung führen. Diese Schwachstelle betrifft Control-M/Server-Versionen 9.0.20.x bis einschließlich 9.0.21.200 und potenziell auch frühere nicht unterstützte Versionen.
Metriken
Weakness-Klassen (CWE)
CWE-305Base
Authentication Bypass by Primary Weakness
The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- New CVE Received2026-07-01 08:16 UTC· cert@airbus.com
- Affected: Control-M/Server
- Description: A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain conditions, this issue may allow an unauthenticated attacker to execute unauthorized commands on the affected server, potentially leading to compromise of the server. This vulnerability affects Control-M/Server versions 9.0.20.x to 9.0.21.200 (included) and potentially earlier unsupported versions.
- CVSS V4.0: AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- CVSS V3.1: AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H