Threat reportVulnerabilityTL-2026-1516
BMC FootPrints ITSM Pre-Auth RCE Chain via Auth Bypass + Java Deserialization (CVE-2025-71257/71258/71259/71260)
BMC FootPrints ITSM Pre-Auth RCE Chain via Auth Bypass + (TL-2026-1516), also tracked as WT-2025-0069, is a critical-severity software vulnerability scored CVSS 9.1, first published 2026-03-18. It has no confirmed attribution, affects BMC Software FootPrints ITSM, references 4 CVEs (CVE-2025-71257, CVE-2025-71258, CVE-2025-71259), maps to 15 MITRE ATT&CK techniques (T1005, T1027, T1033), and is covered by 9 detection rules and 22 indicators of compromise.
- CVSS
- 9.1/10Critical
- CVEs
- 4Referenced vulnerabilities
- Techniques
- 15MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 22Indicators of compromise
Key facts for TL-2026-1516
- Threat ID
- TL-2026-1516
- Also known as
- WT-2025-0069, WT-2025-0070, WT-2025-0071, WT-2025-0072
- Severity
- CRITICAL
- CVSS
- 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- itservices, government administration, health, finance, education, managedserviceproviders
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 22
Malware and tooling in BMC FootPrints ITSM Pre-Auth RCE Chain via Auth Bypass +
Malware and tooling: Custom JSP web shell (watchTowr PoC), AspectJWeaver gadget chain, ysoserial
How BMC FootPrints ITSM Pre-Auth RCE Chain via Auth Bypass + works
watchTowr Labs disclosed a four-vulnerability exploit chain in BMC FootPrints ITSM (v20.20.02-20.24.01.001) that lets an unauthenticated attacker abuse the password-reset endpoint to obtain a guest SEC_TOKEN, pivot through two SSRF endpoints, and reach an insecure Java deserialization sink in the Mono-based ASP.NET VIEWSTATE handler to write a JSP web shell and gain RCE as LOCAL SERVICE. BMC shipped hotfixes in September 2025; CVEs were assigned March 2026 and disclosed publicly March 18, 2026 with a working Python PoC.
BMC FootPrints ITSM is an on-premises IT service management / help-desk platform. watchTowr Labs identified that the application's Spring Security filter chain contains an exception for the `/passwordreset/request/` endpoint: a custom `GenericGuestAuthenticationFilter` (backed by `PasswordResetRequestAuthenticationFilter`) calls `applyGuestForThisRequest()` before the standard `isAuthenticated()` check, and under qualifying conditions issues a valid opaque `SEC_TOKEN` session cookie (e.g. `87x0EkX5BFHyWaktfxK5gasnc_LfwWtYsCm5yIorFuwaexEtaK`) to an unauthenticated caller (CVE-2025-71257/WT-2025-0069, CWE-306, missing authentication for critical function). watchTowr reached this finding by systematically enumerating the 58 security-filter regex patterns defined in `deployment/non-version-specific/conf/footprints-application-beans.xml`, extracting `web.xml` and decompiling `.class` files to fingerprint which endpoints the filter chain treats as pre-authenticated.
That guest-authenticated `SEC_TOKEN` cookie is sufficient to reach two further endpoints that perform blind server-side request forgery: `/import/searchWeb?url=` (CVE-2025-71258/WT-2025-0070, `dataEncoding` parameter also accepted) and `/externalfeed/RSS?feedUrl=` (CVE-2025-71259/WT-2025-0071), both of which accept attacker-controlled URLs with no allow-listing or destination validation and confirm out-of-band via callback rather than response content — functioning as an internal-network proxy primitive attackers can use to reach otherwise unreachable internal services.
The critical link in the chain is CVE-2025-71260/WT-2025-0072 (CWE-502, deserialization of untrusted data, CVSS 3.1 8.8), rooted in FootPrints' use of Mono (an open-source .NET runtime implemented in Java) to host ASP.NET-style configuration pages. The `/aspnetconfig/` endpoint (routed through `VmwDynamicServlet` -> `GhDynamicHttpServlet`) accepts a `__VIEWSTATE` parameter that is Base64-decoded (serialized Java objects begin with the recognizable `rO0AB` prefix) and passed directly through `getRequestParameterMap()` -> `get_Form()` -> `ObjectInputStream.readObject()` inside `Mainsoft/Web/Hosting/BaseFacesStateManager.class` with no type filtering. watchTowr found that the parameter is only parsed by the framework when the request Content-Type is `multipart/form-data` (or, alternatively, a GET with a dummy `__VIEWSTATE` plus an `application/x-www-form-urlencoded` body) — a query-string-only VIEWSTATE resolves to null and is not exploitable. Using `ysoserial`'s `AspectJWeaver` gadget (`java -jar ysoserial.jar AspectJWeaver "filename.jsp;BASE64TEXT" | base64`, backed by vulnerable `aspectjweaver-1.9.2` and `commons-collections-3.2.2` on the classpath, gadget attributed to researcher "Jang"), the deserialization is coerced into an arbitrary file write with path-traversal support in the filename parameter, dropping a JSP web shell (e.g., `watchTowr.jsp` in the published PoC, or a randomized filename such as `MNdeu12Wf.jsp` for detection evasion) into the Tomcat web root (`webapps/ROOT/`, under the FootPrints install path `C:\Program Files\BMC Software\FootPrints\web`). Invoking the shell confirms code execution as the `LOCAL SERVICE` account with a working directory under `C:\Program Files\Apache Software Foundation\Tomcat 9.0`; the injected JSP retrieves `user.name` and `user.dir` Java system properties as an immediate post-exploitation discovery step, and file execution requires no separate compilation step since Tomcat interprets JSP directly.
watchTowr additionally notes the Mono/.NET-in-Java implementation detail as an incidental defense-evasion factor: the `__VIEWSTATE` parameter name is conventionally associated with ASP.NET applications, which can mislead defenders and static analysis tooling into treating the deserialization sink as a .NET-specific ViewState issue rather than a Java `ObjectInputStream` vulnerability, and the component's minimal prior CVE history (last CVE in 2014) suggests it received comparatively little security scrutiny prior to this research.
The full chain — guest-token auth bypass -> SSRF-capable pivot -> reach the deserialization sink -> AspectJWeaver gadget -> JSP web shell -> RCE — requires zero credentials and zero user interaction. watchTowr reported all four issues to BMC on 2025-06-06; BMC confirmed reproduction of the RCE on 2025-09-02 and shipped hotfixed builds for every affected release train. CVEs were formally assigned 2026-03-02 and the technical write-up, including a public Python PoC and GitHub repository, was released 2026-03-18.
MITRE ATT&CK techniques used in TL-2026-1516
Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location
Discovery
T1033 System Owner/User Discovery; T1046 Network Service Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery
Execution
T1059 Command and Scripting Interpreter
Command and Control
Initial Access
T1190 Exploit Public-Facing Application
Persistence
Resource Development
T1588.005 Exploits; T1588.006 Vulnerabilities
Reconnaissance
Affected products and versions in BMC FootPrints ITSM Pre-Auth RCE Chain via Auth Bypass +
- BMC Software — FootPrints ITSM
Vulnerable versions: 20.20.02; 20.21.01; 20.21.02; 20.22.01; 20.23.01; 20.24.01.001
Fixed in: 20.20.03.002; 20.21.01.001; 20.21.02.002; 20.22.01.001; 20.23.01.002; 20.24.01
Remediation for BMC FootPrints ITSM Pre-Auth RCE Chain via Auth Bypass +
Patches
- BMC hotfixes for FootPrints 20.20.02 through 20.24.01.001, released 2025-09-02 (per-branch builds: 20.20.03.002, 20.21.02.002, 20.22.01.001, 20.23.01.002, 20.24.01)
Immediate actions
- Apply the BMC-issued hotfix for your FootPrints version (20.20.02, 20.20.03.002, 20.21.01.001, 20.21.02.002, 20.22.01, 20.22.01.001, 20.23.01, 20.23.01.002, or 20.24.01) immediately
- Restrict network access to the FootPrints web interface to trusted internal networks / VPN only until patched
- Monitor for unauthenticated requests to /passwordreset/request/ that result in a SEC_TOKEN cookie being issued
- Audit webapps/ROOT/ and C:\Program Files\BMC Software\FootPrints\web (and other Tomcat web roots) for unexpected .jsp files and recent web.xml modification timestamps
- Search access logs for POST requests to /aspnetconfig/ with multipart/form-data bodies containing a __VIEWSTATE field, especially Base64 values beginning with the rO0AB serialized-object prefix
Workarounds
- Disable or restrict access to /passwordreset/request/, /import/searchWeb, /externalfeed/RSS, and /aspnetconfig/ at a reverse proxy/WAF if hotfixing cannot occur immediately
Longer-term hardening
- Remove or upgrade the vulnerable aspectjweaver-1.9.2 and commons-collections-3.2.2 library versions bundled with FootPrints where feasible
- Deploy egress filtering / outbound proxy allow-listing on the FootPrints host to blunt SSRF-as-internal-proxy impact (CVE-2025-71258, CVE-2025-71259)
- Deploy a WAF/RASP rule blocking multipart POSTs to /aspnetconfig/ containing serialized-object markers in the __VIEWSTATE parameter
- Deploy EDR/behavioral detection on the Tomcat service account (LOCAL SERVICE) for anomalous file-write and process-spawn activity
- Review and harden the footprints-application-beans.xml filter-chain configuration for any other pre-authentication endpoint exceptions
CVEs associated with BMC FootPrints ITSM Pre-Auth RCE Chain via Auth Bypass +
CVE-2025-71257, CVE-2025-71258, CVE-2025-71259, CVE-2025-71260
Weaknesses (CWE) in BMC FootPrints ITSM Pre-Auth RCE Chain via Auth Bypass +
Timeline of BMC FootPrints ITSM Pre-Auth RCE Chain via Auth Bypass +
- watchTowr Labs discloses all four vulnerabilities (auth bypass, two SSRF, deserialization RCE) to BMC
- watchTowr provides BMC with the AspectJWeaver gadget-chain RCE technical details
- BMC acknowledges receipt of the vulnerability report
- BMC confirms reproduction of 3 of the 4 reported vulnerabilities and requests clarification on the RCE impact
- watchTowr supplies a working Python PoC demonstrating the auth-bypass-to-RCE chain
- Extended troubleshooting between watchTowr and BMC; watchTowr supplies file hashes and screenshots of successful exploitation
- BMC reports internal email/communication issues and promises a status update
- BMC confirms successful reproduction of the full RCE chain and releases hotfixes for all affected FootPrints version branches (20.20.02 through 20.24.01)
- CVE-2025-71257, CVE-2025-71258, CVE-2025-71259, and CVE-2025-71260 are formally assigned
- watchTowr Labs publishes full technical write-up, GitHub PoC repository, and the Python exploit chain publicly
- The Hacker News covers the disclosure in its ThreatsDay Bulletin roundup
Sources cited for BMC FootPrints ITSM Pre-Auth RCE Chain via Auth Bypass +
- Thanks ITSM: Threat Actors Have Never Been So Organized (BMC FootPrints Pre-Auth Remote Code Execution Chains)
- watchTowr-vs-BMC-Footprints-RCE PoC repository
- NVD - CVE-2025-71257
- NVD - CVE-2025-71260
- VulnCheck Advisory - BMC FootPrints ITSM Authentication Bypass
- VulnCheck Advisory - BMC FootPrints ITSM VIEWSTATE Deserialization RCE
- BMC FootPrints Release Notes - 2024 Release 01 Patch 2
- CVE-2025-71259: BMC FootPrints ITSM SSRF Vulnerability
- CVE-2025-71258 | THREATINT
- ThreatsDay Bulletin: FortiGate RaaS, Citrix Exploits, MCP Abuse, LiveChat Phish & More
Detection coverage for TL-2026-1516
As of 2026-03-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1516 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.