Improper Access Control in Migration Planner Affects Red Hat Products
CVE-2026-53470
9.6CRITICAL
What is CVE-2026-53470?
An improper access control vulnerability found in the Migration Planner enables authenticated attackers to bypass ownership checks on the /api/v1/sources/{id}/image-url endpoint. This flaw can be exploited to retrieve presigned S3 URLs for Open Virtual Appliance (OVA) images that belong to other users. By exploiting this vulnerability, attackers may download OVA images that could contain sensitive data, such as long-lived JSON Web Tokens (JWTs) and source configurations. This could potentially lead to unauthorized access and modifications to the victim's source, posing a significant risk to user data integrity and confidentiality.