Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-53471

Опубликовано: 10 июн. 2026
Источник: nvd
CVSS3: 9.6
CVSS3: 7.7
EPSS Низкий

Описание

A flaw was found in migration-planner. The agent-API middleware processes JSON Web Tokens (JWTs) for authentication, but its UpdateSourceInventory and UpdateAgentStatus handlers fail to validate the source_id claim within these tokens against the requested source ID. This oversight allows an authenticated attacker with a valid agent token to manipulate data across different tenants, leading to a complete collapse of tenant isolation. This could result in unauthorized overwriting of victim inventory, planting of malicious credential URLs, or corruption of migration assessments.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:kebev2v:migration_assessment:*:*:*:*:*:*:*:*
Версия до 0.13.5 (исключая)

EPSS

Процентиль: 21%
0.00286
Низкий

9.6 Critical

CVSS3

7.7 High

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 9.6
redhat
около 2 месяцев назад

A flaw was found in migration-planner. The agent-API middleware processes JSON Web Tokens (JWTs) for authentication, but its UpdateSourceInventory and UpdateAgentStatus handlers fail to validate the source_id claim within these tokens against the requested source ID. This oversight allows an authenticated attacker with a valid agent token to manipulate data across different tenants, leading to a complete collapse of tenant isolation. This could result in unauthorized overwriting of victim inventory, planting of malicious credential URLs, or corruption of migration assessments.

CVSS3: 9.6
github
около 2 месяцев назад

A flaw was found in migration-planner. The agent-API middleware processes JSON Web Tokens (JWTs) for authentication, but its UpdateSourceInventory and UpdateAgentStatus handlers fail to validate the source_id claim within these tokens against the requested source ID. This oversight allows an authenticated attacker with a valid agent token to manipulate data across different tenants, leading to a complete collapse of tenant isolation. This could result in unauthorized overwriting of victim inventory, planting of malicious credential URLs, or corruption of migration assessments.

EPSS

Процентиль: 21%
0.00286
Низкий

9.6 Critical

CVSS3

7.7 High

CVSS3

Дефекты

CWE-639