Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-53476

Опубликовано: 07 июн. 2026
Источник: redhat
CVSS3: 9.6
EPSS Низкий

Описание

A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal vulnerability. By crafting a specially designed gzipped tarball, the attacker can bypass security checks and write arbitrary files to the system. This could ultimately lead to the execution of unauthorized code on the appliance.

Дополнительная информация

Статус:

Important
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2487233assisted-migration-agent: VDDK Tarball Chained-Symlink Arbitrary File Write

EPSS

Процентиль: 21%
0.00291
Низкий

9.6 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.6
nvd
около 2 месяцев назад

A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal vulnerability. By crafting a specially designed gzipped tarball, the attacker can bypass security checks and write arbitrary files to the system. This could ultimately lead to the execution of unauthorized code on the appliance.

CVSS3: 9.6
github
около 2 месяцев назад

A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal vulnerability. By crafting a specially designed gzipped tarball, the attacker can bypass security checks and write arbitrary files to the system. This could ultimately lead to the execution of unauthorized code on the appliance.

EPSS

Процентиль: 21%
0.00291
Низкий

9.6 Critical

CVSS3