A AegiFlow
CRITICALCVSS 9.1EPSS 0.3%

CVE-2026-53469

Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API

Published
2026-06-10
Modified
2026-08-13
EPSS percentile
22%
Aliases
GHSA-6xvf-9742-48w2
Sources
github-advisory

Summary

A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sending a DELETE request to the /api/v1/sources route, which lacks proper authorization and filtering. This allows for the destruction of all customer data, including sources, agents, and assessments, leading to a critical loss of availability and integrity across the entire SaaS platform.

Affected packages

EcosystemPackageAffected versionsFixed versions
Gogithub.com/kubev2v/migration-planner0.13.5

Remediation: Upgrade to 0.13.5 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.