CVE-2026-53475 Details
Description
A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Security (TLS) connections when communicating with vCenter. This vulnerability allows a Man-in-the-Middle (MITM) attacker to intercept and harvest vCenter administrator credentials. This can lead to unauthorized access to vCenter.
A vulnerability exists in the KubeV2V assisted-migration-agent due to the application hardcoding insecure Transport Layer Security (TLS) connections when communicating with vCenter. This flaw enables a Man-in-the-Middle (MITM) attacker to intercept and collect vCenter administrator credentials, potentially leading to unauthorized access to vCenter. The issue arises because there is no option to verify certificates or provide a CA bundle, leaving connections vulnerable to interception.
The vulnerability has been addressed in a recent update to the KubeV2V assisted-migration-agent. Users should upgrade to the latest version, which includes the necessary fixes to enable proper TLS verification and secure vCenter connections.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-53475 | [email protected] | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2487232 | [email protected] | Issue TrackingThird Party Advisory |
| https://github.com/kubev2v/assisted-migration-agent/pull/268 | [email protected] | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-295 | Improper Certificate Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| kubev2v assisted migration agent | < 2026-06-10 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 16, 2026 | Initial Analysis | [email protected] |
| Jun 10, 2026 | New CVE Received | [email protected] |