CVE-2026-23782
High Severity
Description
An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allows unauthenticated users to obtain both an API identifier and ...
Related Vulnerabilities
- CVE-2026-35601: Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output MEDIUM
- CVE-2026-32930: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Obj HIGH
- CVE-2026-35656: OpenClaw before 2026.3.22 contains an authentication bypass vulnerability in the X-Forwarded-For hea MEDIUM
- CVE-2026-6037: A vulnerability was determined in code-projects Vehicle Showroom Management System 1.0. This affects MEDIUM
- CVE-2026-5144: The BuddyPress Groupblog plugin for WordPress is vulnerable to Privilege Escalation in all versions HIGH
Related Coverage
Threat Actors