A vulnerability labeled as critical has been found in BMC Control-M MFT 9.0.20/9.0.21/9.0.22. Affected is an unknown function of the component API Management Endpoint. Such manipulation leads to improper authentication.

This vulnerability is listed as CVE-2026-23782. The attack may be performed from remote. There is no available exploit.