CVE-2026-3207

Severity CVSS v4.0:
HIGH
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
17/03/2026
Last modified:
02/04/2026

Description

Configuration issue in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tibco:bpm_enterprise:*:*:*:*:*:*:*:* 4.3.0 (including) 4.3.5 (excluding)