CVE-2026-53470: Authorization Bypass Through User-Controlled Key
CVE-2026-53470 is a critical authorization bypass vulnerability in the migration-planner cloud service affecting versions prior to 0.13.5. An authenticated attacker can exploit improper access control in the /api/v1/sources/{id}/image-url endpoint to bypass ownership checks and obtain presigned S3 URLs for OVA images belonging to other users. These images may contain sensitive data such as long-lived agent JWTs and source configurations, potentially enabling unauthorized access and modification of victim sources. A patch is available, and the vendor manages remediation for this cloud-hosted service.
AI Analysis
Technical Summary
CVE-2026-53470 is an authorization bypass vulnerability in migration-planner versions before 0.13.5. The flaw exists in the /api/v1/sources/{id}/image-url endpoint, where access control checks are improperly implemented, allowing authenticated users to bypass ownership verification and retrieve presigned S3 URLs for Open Virtual Appliance (OVA) images of other users. These images may contain sensitive information including long-lived agent JSON Web Tokens and source configurations, which could lead to unauthorized access and modification of victim sources. The vulnerability has a CVSS v3.1 score of 9.6 (critical). The affected product is a cloud service, and remediation is managed by the vendor. Red Hat's advisory notes that this vulnerability does not affect any currently supported Red Hat product but maintains the record for completeness.
Potential Impact
The vulnerability allows an authenticated attacker to bypass ownership checks and access presigned URLs for OVA images belonging to other users. This can expose sensitive data such as long-lived agent JWTs and source configurations, potentially enabling unauthorized access and modification of victim sources. The impact includes horizontal privilege escalation and possible unauthorized data disclosure. The CVSS score of 9.6 reflects critical severity with high confidentiality and integrity impact, but no availability impact.
Mitigation Recommendations
A patch is available for migration-planner versions prior to 0.13.5. Since the affected product is a cloud service, the vendor manages remediation server-side. Users should verify with the vendor advisory for confirmation of applied fixes. No additional action is required if using the cloud service as the vendor handles patching.
CVE-2026-53470: Authorization Bypass Through User-Controlled Key
Description
CVE-2026-53470 is a critical authorization bypass vulnerability in the migration-planner cloud service affecting versions prior to 0.13.5. An authenticated attacker can exploit improper access control in the /api/v1/sources/{id}/image-url endpoint to bypass ownership checks and obtain presigned S3 URLs for OVA images belonging to other users. These images may contain sensitive data such as long-lived agent JWTs and source configurations, potentially enabling unauthorized access and modification of victim sources. A patch is available, and the vendor manages remediation for this cloud-hosted service.
CVSS v3.1
Score 9.6critical
Affected software
pkg:github/migration-plannerRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-53470 is an authorization bypass vulnerability in migration-planner versions before 0.13.5. The flaw exists in the /api/v1/sources/{id}/image-url endpoint, where access control checks are improperly implemented, allowing authenticated users to bypass ownership verification and retrieve presigned S3 URLs for Open Virtual Appliance (OVA) images of other users. These images may contain sensitive information including long-lived agent JSON Web Tokens and source configurations, which could lead to unauthorized access and modification of victim sources. The vulnerability has a CVSS v3.1 score of 9.6 (critical). The affected product is a cloud service, and remediation is managed by the vendor. Red Hat's advisory notes that this vulnerability does not affect any currently supported Red Hat product but maintains the record for completeness.
Potential Impact
The vulnerability allows an authenticated attacker to bypass ownership checks and access presigned URLs for OVA images belonging to other users. This can expose sensitive data such as long-lived agent JWTs and source configurations, potentially enabling unauthorized access and modification of victim sources. The impact includes horizontal privilege escalation and possible unauthorized data disclosure. The CVSS score of 9.6 reflects critical severity with high confidentiality and integrity impact, but no availability impact.
Mitigation Recommendations
A patch is available for migration-planner versions prior to 0.13.5. Since the affected product is a cloud service, the vendor manages remediation server-side. Users should verify with the vendor advisory for confirmation of applied fixes. No additional action is required if using the cloud service as the vendor handles patching.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-06-09T17:03:29.627Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Is Cloud Service
- true
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-53470","vendor":"Red Hat"}]
Threat ID: 6a29799fc9170919df2daed3
Added to database: 06/10/2026, 14:50:07 UTC
Last enriched: 08/14/2026, 16:38:38 UTC
Last updated: 09/12/2026, 22:01:34 UTC
Views: 118
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.