CVE-2026-10540
The Control-M/Enterprise Manager uses weak protections for stored hashes of account passwords, potentially allowing offline password recovery attacks if credential data is obtained by an attacker. This vulnerability affects Control-M/Enterprise Manager unsupported versions 9.0.20.x and potentially earlier unsupported versions
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.6
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.11%
- CWE
- CWE-328
- Published
- 2026-07-01
- Last modified
- 2026-07-01
Affected products
- BMC Control-M/Enterprise Manager
- BMC Control-M/Enterprise Manager
Weakness type
Related vulnerabilities
- CVE-2026-15605 — wandb Artifact Integrity Validation hashutil.py ArtifactManifestEntry.download weak hash
- CVE-2026-41879 — Weak password hashing in R-SOFT DMS
- CVE-2026-14742 — langchain-ai langgraph Task Result Cache _cache.py _freeze weak hash
- CVE-2026-14738 — exo-explore exo Vision Feature Cache vision.py _image_cache_key weak hash
- CVE-2026-14630 — ForceInjection AI-fundermentals Memory Recall smart_customer_service.py get_conversation_history weak hash
- CVE-2026-13455 — PostgreSQL Anonymizer: Unrestricted function can leak the secret salt
- CVE-2026-53692 — Weak hashing algorithm in Redeight CMS
- CVE-2026-13510 — SimStudioAI sim Password Protection deployment.ts weak hash