CVE-2026-10539

A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain conditions, this issue may allow an unauthenticated attacker to execute unauthorized commands on the affected server, potentially leading to compromise of the server.  This vulnerability affects Control-M/Server versions 9.0.20.x to 9.0.21.200 (included) and potentially earlier unsupported versions.

Scoring

Severity
CRITICAL
CVSS base score
9.5
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
EPSS probability
0.42%
CWE
CWE-305
Published
2026-07-01
Last modified
2026-07-01

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs