CVE-2026-10539
CRITICALUnauthenticated command injection in Control-M/Server communication command
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-10539. PoCs published by HermesNA-1.
AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2026-10539, a command injection vulnerability in Control-M/Server's communication command due to insufficient input sanitization. The code includes placeholder logic but lacks actual exploit implementation.
Description
A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain conditions, this issue may allow an unauthenticated attacker to execute unauthorized commands on the affected server, potentially leading to compromise of the server. This vulnerability affects Control-M/Server versions 9.0.20.x to 9.0.21.200 (included) and potentially earlier unsupported versions.
Exploits (1)
This repository contains an auto-generated stub module for CVE-2026-10539, a command injection vulnerability in Control-M/Server's communication command due to insufficient input sanitization. The code includes placeholder logic but lacks actual exploit implementation.
References (1)
Scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H