Threat reportVulnerabilityTL-2026-1516

BMC FootPrints ITSM Pre-Auth RCE Chain via Auth Bypass + Java Deserialization (CVE-2025-71257/71258/71259/71260)

criticalACTIVE

BMC FootPrints ITSM Pre-Auth RCE Chain via Auth Bypass + (TL-2026-1516), also tracked as WT-2025-0069, is a critical-severity software vulnerability scored CVSS 9.1, first published 2026-03-18. It has no confirmed attribution, affects BMC Software FootPrints ITSM, references 4 CVEs (CVE-2025-71257, CVE-2025-71258, CVE-2025-71259), maps to 15 MITRE ATT&CK techniques (T1005, T1027, T1033), and is covered by 9 detection rules and 22 indicators of compromise.

CVSS
9.1/10Critical
CVEs
4Referenced vulnerabilities
Techniques
15MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
22Indicators of compromise

Key facts for TL-2026-1516

Threat ID
TL-2026-1516
Also known as
WT-2025-0069, WT-2025-0070, WT-2025-0071, WT-2025-0072
Severity
CRITICAL
CVSS
9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
itservices, government administration, health, finance, education, managedserviceproviders
Target regions
Global
Detection rules
9
Indicators of compromise
22

Malware and tooling in BMC FootPrints ITSM Pre-Auth RCE Chain via Auth Bypass +

Malware and tooling: Custom JSP web shell (watchTowr PoC), AspectJWeaver gadget chain, ysoserial

How BMC FootPrints ITSM Pre-Auth RCE Chain via Auth Bypass + works

watchTowr Labs disclosed a four-vulnerability exploit chain in BMC FootPrints ITSM (v20.20.02-20.24.01.001) that lets an unauthenticated attacker abuse the password-reset endpoint to obtain a guest SEC_TOKEN, pivot through two SSRF endpoints, and reach an insecure Java deserialization sink in the Mono-based ASP.NET VIEWSTATE handler to write a JSP web shell and gain RCE as LOCAL SERVICE. BMC shipped hotfixes in September 2025; CVEs were assigned March 2026 and disclosed publicly March 18, 2026 with a working Python PoC.

BMC FootPrints ITSM is an on-premises IT service management / help-desk platform. watchTowr Labs identified that the application's Spring Security filter chain contains an exception for the `/passwordreset/request/` endpoint: a custom `GenericGuestAuthenticationFilter` (backed by `PasswordResetRequestAuthenticationFilter`) calls `applyGuestForThisRequest()` before the standard `isAuthenticated()` check, and under qualifying conditions issues a valid opaque `SEC_TOKEN` session cookie (e.g. `87x0EkX5BFHyWaktfxK5gasnc_LfwWtYsCm5yIorFuwaexEtaK`) to an unauthenticated caller (CVE-2025-71257/WT-2025-0069, CWE-306, missing authentication for critical function). watchTowr reached this finding by systematically enumerating the 58 security-filter regex patterns defined in `deployment/non-version-specific/conf/footprints-application-beans.xml`, extracting `web.xml` and decompiling `.class` files to fingerprint which endpoints the filter chain treats as pre-authenticated.

That guest-authenticated `SEC_TOKEN` cookie is sufficient to reach two further endpoints that perform blind server-side request forgery: `/import/searchWeb?url=` (CVE-2025-71258/WT-2025-0070, `dataEncoding` parameter also accepted) and `/externalfeed/RSS?feedUrl=` (CVE-2025-71259/WT-2025-0071), both of which accept attacker-controlled URLs with no allow-listing or destination validation and confirm out-of-band via callback rather than response content — functioning as an internal-network proxy primitive attackers can use to reach otherwise unreachable internal services.

The critical link in the chain is CVE-2025-71260/WT-2025-0072 (CWE-502, deserialization of untrusted data, CVSS 3.1 8.8), rooted in FootPrints' use of Mono (an open-source .NET runtime implemented in Java) to host ASP.NET-style configuration pages. The `/aspnetconfig/` endpoint (routed through `VmwDynamicServlet` -> `GhDynamicHttpServlet`) accepts a `__VIEWSTATE` parameter that is Base64-decoded (serialized Java objects begin with the recognizable `rO0AB` prefix) and passed directly through `getRequestParameterMap()` -> `get_Form()` -> `ObjectInputStream.readObject()` inside `Mainsoft/Web/Hosting/BaseFacesStateManager.class` with no type filtering. watchTowr found that the parameter is only parsed by the framework when the request Content-Type is `multipart/form-data` (or, alternatively, a GET with a dummy `__VIEWSTATE` plus an `application/x-www-form-urlencoded` body) — a query-string-only VIEWSTATE resolves to null and is not exploitable. Using `ysoserial`'s `AspectJWeaver` gadget (`java -jar ysoserial.jar AspectJWeaver "filename.jsp;BASE64TEXT" | base64`, backed by vulnerable `aspectjweaver-1.9.2` and `commons-collections-3.2.2` on the classpath, gadget attributed to researcher "Jang"), the deserialization is coerced into an arbitrary file write with path-traversal support in the filename parameter, dropping a JSP web shell (e.g., `watchTowr.jsp` in the published PoC, or a randomized filename such as `MNdeu12Wf.jsp` for detection evasion) into the Tomcat web root (`webapps/ROOT/`, under the FootPrints install path `C:\Program Files\BMC Software\FootPrints\web`). Invoking the shell confirms code execution as the `LOCAL SERVICE` account with a working directory under `C:\Program Files\Apache Software Foundation\Tomcat 9.0`; the injected JSP retrieves `user.name` and `user.dir` Java system properties as an immediate post-exploitation discovery step, and file execution requires no separate compilation step since Tomcat interprets JSP directly.

watchTowr additionally notes the Mono/.NET-in-Java implementation detail as an incidental defense-evasion factor: the `__VIEWSTATE` parameter name is conventionally associated with ASP.NET applications, which can mislead defenders and static analysis tooling into treating the deserialization sink as a .NET-specific ViewState issue rather than a Java `ObjectInputStream` vulnerability, and the component's minimal prior CVE history (last CVE in 2014) suggests it received comparatively little security scrutiny prior to this research.

The full chain — guest-token auth bypass -> SSRF-capable pivot -> reach the deserialization sink -> AspectJWeaver gadget -> JSP web shell -> RCE — requires zero credentials and zero user interaction. watchTowr reported all four issues to BMC on 2025-06-06; BMC confirmed reproduction of the RCE on 2025-09-02 and shipped hotfixed builds for every affected release train. CVEs were formally assigned 2026-03-02 and the technical write-up, including a public Python PoC and GitHub repository, was released 2026-03-18.

MITRE ATT&CK techniques used in TL-2026-1516

Collection

T1005 Data from Local System

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location

Discovery

T1033 System Owner/User Discovery; T1046 Network Service Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1090.004 Domain Fronting

Initial Access

T1190 Exploit Public-Facing Application

Persistence

T1505.003 Web Shell

Resource Development

T1588.005 Exploits; T1588.006 Vulnerabilities

Reconnaissance

T1592.002 Software

Affected products and versions in BMC FootPrints ITSM Pre-Auth RCE Chain via Auth Bypass +

  • BMC Software — FootPrints ITSM
    Vulnerable versions: 20.20.02; 20.21.01; 20.21.02; 20.22.01; 20.23.01; 20.24.01.001
    Fixed in: 20.20.03.002; 20.21.01.001; 20.21.02.002; 20.22.01.001; 20.23.01.002; 20.24.01

Remediation for BMC FootPrints ITSM Pre-Auth RCE Chain via Auth Bypass +

Patches

  • BMC hotfixes for FootPrints 20.20.02 through 20.24.01.001, released 2025-09-02 (per-branch builds: 20.20.03.002, 20.21.02.002, 20.22.01.001, 20.23.01.002, 20.24.01)

Immediate actions

  • Apply the BMC-issued hotfix for your FootPrints version (20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, or 20.24.01) immediately
  • Restrict network access to the FootPrints web interface to trusted internal networks / VPN only until patched
  • Monitor for unauthenticated requests to /passwordreset/request/ that result in a SEC_TOKEN cookie being issued
  • Audit webapps/ROOT/ and C:\Program Files\BMC Software\FootPrints\web (and other Tomcat web roots) for unexpected .jsp files and recent web.xml modification timestamps
  • Search access logs for POST requests to /aspnetconfig/ with multipart/form-data bodies containing a __VIEWSTATE field, especially Base64 values beginning with the rO0AB serialized-object prefix

Workarounds

  • Disable or restrict access to /passwordreset/request/, /import/searchWeb, /externalfeed/RSS, and /aspnetconfig/ at a reverse proxy/WAF if hotfixing cannot occur immediately

Longer-term hardening

  • Remove or upgrade the vulnerable aspectjweaver-1.9.2 and commons-collections-3.2.2 library versions bundled with FootPrints where feasible
  • Deploy egress filtering / outbound proxy allow-listing on the FootPrints host to blunt SSRF-as-internal-proxy impact (CVE-2025-71258, CVE-2025-71259)
  • Deploy a WAF/RASP rule blocking multipart POSTs to /aspnetconfig/ containing serialized-object markers in the __VIEWSTATE parameter
  • Deploy EDR/behavioral detection on the Tomcat service account (LOCAL SERVICE) for anomalous file-write and process-spawn activity
  • Review and harden the footprints-application-beans.xml filter-chain configuration for any other pre-authentication endpoint exceptions

CVEs associated with BMC FootPrints ITSM Pre-Auth RCE Chain via Auth Bypass +

CVE-2025-71257, CVE-2025-71258, CVE-2025-71259, CVE-2025-71260

Weaknesses (CWE) in BMC FootPrints ITSM Pre-Auth RCE Chain via Auth Bypass +

CWE-306, CWE-502, CWE-918

Timeline of BMC FootPrints ITSM Pre-Auth RCE Chain via Auth Bypass +

  • watchTowr Labs discloses all four vulnerabilities (auth bypass, two SSRF, deserialization RCE) to BMC
  • watchTowr provides BMC with the AspectJWeaver gadget-chain RCE technical details
  • BMC acknowledges receipt of the vulnerability report
  • BMC confirms reproduction of 3 of the 4 reported vulnerabilities and requests clarification on the RCE impact
  • watchTowr supplies a working Python PoC demonstrating the auth-bypass-to-RCE chain
  • Extended troubleshooting between watchTowr and BMC; watchTowr supplies file hashes and screenshots of successful exploitation
  • BMC reports internal email/communication issues and promises a status update
  • BMC confirms successful reproduction of the full RCE chain and releases hotfixes for all affected FootPrints version branches (20.20.02 through 20.24.01)
  • CVE-2025-71257, CVE-2025-71258, CVE-2025-71259, and CVE-2025-71260 are formally assigned
  • watchTowr Labs publishes full technical write-up, GitHub PoC repository, and the Python exploit chain publicly
  • The Hacker News covers the disclosure in its ThreatsDay Bulletin roundup

Sources cited for BMC FootPrints ITSM Pre-Auth RCE Chain via Auth Bypass +

Detection coverage for TL-2026-1516

As of 2026-03-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1516 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
22 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats