Path Traversal Vulnerability in Assisted Migration Agent by Red Hat
CVE-2026-53476

9.6CRITICAL

Key Information:

Vendor

Red Hat

Status
Vendor
CVE Published:
10 June 2026

What is CVE-2026-53476?

A vulnerability exists in the Assisted Migration Agent, where an unauthenticated attacker on the same local area network can exploit a path traversal flaw. By creating a specially crafted gzipped tarball, the attacker may bypass critical security measures and write arbitrary files to the affected system. This could potentially allow the execution of unauthorized code, posing significant risks to the integrity and confidentiality of the appliance.

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.