CVE-2026-53471

A flaw was found in migration-planner. The agent-API middleware processes JSON Web Tokens (JWTs) for authentication, but its UpdateSourceInventory and UpdateAgentStatus handlers fail to validate the source_id claim within these tokens against the requested source ID. This oversight allows an authenticated attacker with a valid agent token to manipulate data across different tenants, leading to a complete collapse of tenant isolation. This could result in unauthorized overwriting of victim inventory, planting of malicious credential URLs, or corruption of migration assessments.
Configurations

Configuration 1 (hide)

cpe:2.3:a:kebev2v:migration_assessment:*:*:*:*:*:*:*:*

History

17 Jun 2026, 14:45

Type Values Removed Values Added
References () https://access.redhat.com/security/cve/CVE-2026-53471 - () https://access.redhat.com/security/cve/CVE-2026-53471 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2487070 - () https://bugzilla.redhat.com/show_bug.cgi?id=2487070 - Issue Tracking, Third Party Advisory
References () https://github.com/kubev2v/migration-planner/pull/1213 - () https://github.com/kubev2v/migration-planner/pull/1213 - Patch
First Time Kebev2v
Kebev2v migration Assessment
CPE cpe:2.3:a:kebev2v:migration_assessment:*:*:*:*:*:*:*:*

10 Jun 2026, 16:17

Type Values Removed Values Added
CWE CWE-639

10 Jun 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-10 15:16

Updated : 2026-06-17 14:45


NVD link : CVE-2026-53471

Mitre link : CVE-2026-53471

CVE.ORG link : CVE-2026-53471


JSON object : View

Products Affected

kebev2v

  • migration_assessment
CWE
CWE-639

Authorization Bypass Through User-Controlled Key