PT-2026-48445 · Unknown · Migration-Planner

CVE-2026-53471

·

Published

2026-06-10

·

Updated

2026-09-04

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions migration-planner (affected versions not specified)
Description The agent-API middleware processes JSON Web Tokens (JWTs) for authentication, but the UpdateSourceInventory and UpdateAgentStatus handlers do not validate the source id claim within the tokens against the requested source ID. This allows an authenticated attacker with a valid agent token to manipulate data across different tenants, causing a collapse of tenant isolation. Potential impacts include unauthorized overwriting of victim inventory, planting of malicious credential URLs, or corruption of migration assessments.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53471
GHSA-2FQW-7C6R-2CQ6
GO-2026-6228
OPENSUSE-SU-2026:21761-1

Affected Products

Migration-Planner