CVE-2026-10538EPSS p16.2%
CVE-2026-10538CVE-2026-10538
Description
Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowed object types in the out of support Control-M/Server and Control-M/Enterprise Manager versions 9.0.20.x and potentially earlier. This issue may allow an authenticated attacker to trigger unintended server-side behavior through crafted serialized content.
Scoring
| CVSS | 8.0 () |
| Vector | CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 0.25% probability of exploitation · percentile 16.2% · 2026-08-15T12:02:44Z |
| Last modified | 2026-07-01 |