PT-2026-48445 · Unknown · Migration-Planner
CVE-2026-53471
·
Published
2026-06-10
·
Updated
2026-09-04
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
migration-planner (affected versions not specified)
Description
The agent-API middleware processes JSON Web Tokens (JWTs) for authentication, but the
UpdateSourceInventory and UpdateAgentStatus handlers do not validate the source id claim within the tokens against the requested source ID. This allows an authenticated attacker with a valid agent token to manipulate data across different tenants, causing a collapse of tenant isolation. Potential impacts include unauthorized overwriting of victim inventory, planting of malicious credential URLs, or corruption of migration assessments.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Migration-Planner