Home

Description

A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sending a DELETE request to the /api/v1/sources route, which lacks proper authorization and filtering. This allows for the destruction of all customer data, including sources, agents, and assessments, leading to a critical loss of availability and integrity across the entire SaaS platform.

PUBLISHED Reserved 2026-06-09 | Published 2026-06-10 | Updated 2026-06-10 | Assigner redhat




CRITICAL: 9.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Problem types

Missing Authentication for Critical Function

Product status

Default status
unaffected

Any version before 0.13.5
affected

Timeline

2026-06-09:Reported to Red Hat.
2026-06-07:Made public.

References

access.redhat.com/security/cve/CVE-2026-53469 vdb-entry

bugzilla.redhat.com/show_bug.cgi?id=2487065 (RHBZ#2487065) issue-tracking

github.com/kubev2v/migration-planner/pull/1227

cve.org (CVE-2026-53469)

nvd.nist.gov (CVE-2026-53469)

Download JSON