A flaw was found in migration-planner. An authenticated attacker could exploit an improper access control vulnerability in the `/api/v1/sources/{id}/image-url` endpoint. This flaw allows the attacker to bypass an ownership check and obtain presigned S3 URLs for Open Virtual Appliance (OVA) images belonging to other users. Consequently, the attacker can download OVA images containing sensitive information, such as long-lived agent JSON Web Tokens (JWTs) and source configurations, potentially leading to unauthorized access and modification of the victim's source.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/security/cve/CVE-2026-53470 | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2487069 | Issue Tracking Third Party Advisory |
| https://github.com/kubev2v/migration-planner/pull/1218 | Patch |
Configurations
History
17 Jun 2026, 14:28
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:kebev2v:migration_assessment:*:*:*:*:*:*:*:* | |
| First Time |
Kebev2v
Kebev2v migration Assessment |
|
| References | () https://access.redhat.com/security/cve/CVE-2026-53470 - Third Party Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2487069 - Issue Tracking, Third Party Advisory | |
| References | () https://github.com/kubev2v/migration-planner/pull/1218 - Patch |
10 Jun 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-10 15:16
Updated : 2026-06-17 14:28
NVD link : CVE-2026-53470
Mitre link : CVE-2026-53470
CVE.ORG link : CVE-2026-53470
JSON object : View
Products Affected
kebev2v
- migration_assessment
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
