CVE-2026-23782
High Severity
Description
An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allows unauthenticated users to obtain both an API identifier and ...
Related Vulnerabilities
- CVE-2026-4351: The Perfmatters plugin for WordPress is vulnerable to arbitrary file overwrite via path traversal in HIGH
- CVE-2026-35599: Vikunja has Algorithmic Complexity DoS in Repeating Task Handler MEDIUM
- CVE-2026-5500: wolfSSL's wc_PKCS7_DecodeAuthEnvelopedData() does not properly sanitize the AES-GCM authentication t HIGH
- CVE-2026-34983: Wasmtime has use-after-free bug after cloning `wasmtime::Linker` LOW
- CVE-2026-5479: In wolfSSL's EVP layer, the ChaCha20-Poly1305 AEAD decryption path in wolfSSL_EVP_CipherFinal (and r HIGH
Related Coverage
Threat Actors