CVE-2026-53470 Details
Description
A flaw was found in migration-planner. An authenticated attacker could exploit an improper access control vulnerability in the `/api/v1/sources/{id}/image-url` endpoint. This flaw allows the attacker to bypass an ownership check and obtain presigned S3 URLs for Open Virtual Appliance (OVA) images belonging to other users. Consequently, the attacker can download OVA images containing sensitive information, such as long-lived agent JSON Web Tokens (JWTs) and source configurations, potentially leading to unauthorized access and modification of the victim's source.
An improper access control vulnerability has been identified in the KubeV2V Migration Planner. This vulnerability allows authenticated attackers to bypass ownership checks in the '/api/v1/sources/{id}/image-url' endpoint, enabling them to access presigned S3 URLs for Open Virtual Appliance (OVA) images belonging to other users. The OVA images may contain sensitive information, such as long-lived agent JSON Web Tokens (JWTs) and source configurations, which could lead to unauthorized access and modification of the victim's source.
The vulnerability has been addressed in a recent update, which added the missing organization check to the 'GetSourceDownloadURL' endpoint. Users should ensure they are using the latest version of the KubeV2V Migration Planner.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-53470 | [email protected] | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2487069 | [email protected] | Issue TrackingThird Party Advisory |
| https://github.com/kubev2v/migration-planner/pull/1218 | [email protected] | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| kebev2v migration assessment | < 0.13.5 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 10, 2026 | New CVE Received | [email protected] |