Improper Access Control in Migration Planner Affects Red Hat Products
CVE-2026-53470

9.6CRITICAL

Key Information:

Vendor

Red Hat

Status
Vendor
CVE Published:
10 June 2026

What is CVE-2026-53470?

An improper access control vulnerability found in the Migration Planner enables authenticated attackers to bypass ownership checks on the /api/v1/sources/{id}/image-url endpoint. This flaw can be exploited to retrieve presigned S3 URLs for Open Virtual Appliance (OVA) images that belong to other users. By exploiting this vulnerability, attackers may download OVA images that could contain sensitive data, such as long-lived JSON Web Tokens (JWTs) and source configurations. This could potentially lead to unauthorized access and modifications to the victim's source, posing a significant risk to user data integrity and confidentiality.

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.