PT-2026-71196 · Microsoft · Container-Migration-Solution-Accelerator
CVE-2026-73298
·
Published
2026-08-12
·
Updated
2026-08-12
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Microsoft Container Migration Solution Accelerator versions prior to 2.1.3
Description
An authenticated Insecure Direct Object Reference (IDOR)—a flaw where an application provides direct access to objects based on user-supplied input—exists in the process and file management APIs. Due to missing ownership checks, authenticated users can read, write, and delete processes and files belonging to other authenticated users within the same organization. While the application uses Entra ID for authentication, it lacks the necessary authorization controls to prevent unauthorized access and modification of migration data across different users.
Recommendations
Update to a version newer than 2.1.2.
Restrict access to the process and file management APIs to minimize the risk of unauthorized data modification until the update is applied.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Container-Migration-Solution-Accelerator