PT-2026-48447 · Unknown · Migration-Planner

CVE-2026-53474

·

Published

2026-06-10

·

Updated

2026-09-04

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions migration-planner (affected versions not specified)
Description A remote authenticated attacker can exploit a flaw by uploading a specially crafted RVTools .xlsx file. Due to improper input sanitization, malicious SQL embedded within a spreadsheet cell is executed during the processing of cluster names. This SQL Injection enables arbitrary file reading on the system, which may expose sensitive data such as Kubernetes service account tokens and other credentials, potentially leading to a full compromise of the SaaS environment.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53474
GHSA-VF2H-7X3W-97FR
GO-2026-6233
OPENSUSE-SU-2026:21761-1

Affected Products

Migration-Planner