PT-2026-71196 · Microsoft · Container-Migration-Solution-Accelerator

CVE-2026-73298

·

Published

2026-08-12

·

Updated

2026-08-12

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Microsoft Container Migration Solution Accelerator versions prior to 2.1.3
Description An authenticated Insecure Direct Object Reference (IDOR)—a flaw where an application provides direct access to objects based on user-supplied input—exists in the process and file management APIs. Due to missing ownership checks, authenticated users can read, write, and delete processes and files belonging to other authenticated users within the same organization. While the application uses Entra ID for authentication, it lacks the necessary authorization controls to prevent unauthorized access and modification of migration data across different users.
Recommendations Update to a version newer than 2.1.2. Restrict access to the process and file management APIs to minimize the risk of unauthorized data modification until the update is applied.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73298
GHSA-27MC-PCCP-3X2X

Affected Products

Container-Migration-Solution-Accelerator