CVE-2025-55115
A path traversal in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent. This vulnerability impacts the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions. This vulnerability was fixed in 9.0.20.100 and above.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.3
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- EPSS probability
- 0.17%
- CWE
- CWE-23
- Published
- 2025-09-16
- Last modified
- 2026-03-12
Affected products
- BMC Control-M/Agent
- BMC Control-M/Agent
- BMC Control-M/Agent
- BMC Control-M/Agent
- BMC Control-M/Agent
Weakness type
Related vulnerabilities
- CVE-2026-84939 — Apache FreeMarker, Apache FreeMarker: A malformed locale may be exploitable for path traversal attacks
- CVE-2026-15913 — Path Traversal in Fortra's GoAnywhere MFT Endpoint
- CVE-2026-79728 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-87747 — Ragic|Enterprise Cloud Database - Arbitrary File Read
- CVE-2026-47680 — Source controller: Improper path handling allows traversal
- CVE-2026-77897 — Microsoft Power Automate Desktop Elevation of Privilege Vulnerability
- CVE-2026-72948 — Windows DNS Elevation of Privilege Vulnerability
- CVE-2026-67367 — A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE...