Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-53469 2 Kebev2v, Kubev2v 2 Migration Assessment, Migration-planner 2026-06-11 9.1 Critical
A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sending a DELETE request to the /api/v1/sources route, which lacks proper authorization and filtering. This allows for the destruction of all customer data, including sources, agents, and assessments, leading to a critical loss of availability and integrity across the entire SaaS platform.
CVE-2026-53471 2 Kebev2v, Kubev2v 2 Migration Assessment, Migration-planner 2026-06-11 9.6 Critical
A flaw was found in migration-planner. The agent-API middleware processes JSON Web Tokens (JWTs) for authentication, but its UpdateSourceInventory and UpdateAgentStatus handlers fail to validate the source_id claim within these tokens against the requested source ID. This oversight allows an authenticated attacker with a valid agent token to manipulate data across different tenants, leading to a complete collapse of tenant isolation. This could result in unauthorized overwriting of victim inventory, planting of malicious credential URLs, or corruption of migration assessments.