Critical severity9.6NVD Advisory· Published Jun 10, 2026· Updated Jun 10, 2026
CVE-2026-53471
CVE-2026-53471
Description
A flaw was found in migration-planner. The agent-API middleware processes JSON Web Tokens (JWTs) for authentication, but its UpdateSourceInventory and UpdateAgentStatus handlers fail to validate the source_id claim within these tokens against the requested source ID. This oversight allows an authenticated attacker with a valid agent token to manipulate data across different tenants, leading to a complete collapse of tenant isolation. This could result in unauthorized overwriting of victim inventory, planting of malicious credential URLs, or corruption of migration assessments.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/kubev2v/migration-plannerGo | < 0.13.5 | 0.13.5 |
Affected products
2Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-2fqw-7c6r-2cq6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-53471ghsaADVISORY
- access.redhat.com/security/cve/CVE-2026-53471nvdWEB
- bugzilla.redhat.com/show_bug.cginvdWEB
- github.com/kubev2v/migration-planner/commit/fd21a239216f5eeec635d16c72be9c033bd5d1aaghsaWEB
- github.com/kubev2v/migration-planner/pull/1213nvdWEB
News mentions
0No linked articles in our index yet.