Critical severity9.6NVD Advisory· Published Jun 10, 2026· Updated Jun 16, 2026
CVE-2026-53476
CVE-2026-53476
Description
A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal vulnerability. By crafting a specially designed gzipped tarball, the attacker can bypass security checks and write arbitrary files to the system. This could ultimately lead to the execution of unauthorized code on the appliance.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/kubev2v/assisted-migration-agentGo | < 0.16.0 | 0.16.0 |
Affected products
3(expand)+ 2 more
- (no CPE)
- cpe:2.3:a:kubev2v:assisted_migration_agent:*:*:*:*:*:*:*:*range: <2026-06-07
- (no CPE)
Patches
Vulnerability mechanics
References
6- github.com/kubev2v/assisted-migration-agent/pull/256nvdPatchWEB
- access.redhat.com/security/cve/CVE-2026-53476nvdThird Party AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-7j4w-x8x8-5mvgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-53476ghsaADVISORY
- github.com/kubev2v/assisted-migration-agent/commit/bcae0438ad8386321a300413d71c982a11b7b5b7ghsaWEB
News mentions
0No linked articles in our index yet.