PT-2026-48448 · Vmware · Vcenter+1

CVE-2026-53475

·

Published

2026-06-10

·

Updated

2026-09-04

CVSS v3.1

9.3

Critical

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions assisted-migration-agent (affected versions not specified)
Description The application hardcodes insecure Transport Layer Security (TLS) connections when communicating with vCenter. This design flaw allows a Man-in-the-Middle (MITM) attacker to intercept and decrypt network traffic, enabling the harvesting of vCenter administrator credentials without requiring prior authentication. Successful exploitation can lead to unauthorized access and full administrative control over the vCenter environment.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53475
GHSA-8G5P-JXP9-457C
GO-2026-6232
OPENSUSE-SU-2026:21761-1

Affected Products

Assisted-Migration-Agent
Vcenter