Cross-Site Scripting Vulnerability in Migration-Planner by Red Hat
CVE-2026-53472

6.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
14 August 2026

What is CVE-2026-53472?

A notable flaw has been identified in the migration-planner product by Red Hat. This issue stems from inadequate validation of the 'AgentStatusUpdate.CredentialUrl' field. As a result, an authenticated attacker can exploit this vulnerability by inserting a malicious 'javascript:' URL. When unsuspecting users interact with this URL in the Hybrid Cloud Console, it can trigger Cross-Site Scripting (XSS) attacks. Such attacks enable unauthorized script execution during a user’s session, which may lead to the exposure of sensitive user data.

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.