CVE-2026-53469Critical· 9.1▾ MidnightOpenshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sending a DELETE request to the /api/v1/sources route, which lacks proper authorization and filtering. This allows for the destruction of all customer data, including sources, agents, and assessments, leading to a critical loss of availability and integrity across the entire SaaS platform.
github.com/kubev2v/migration-planner < 0.13.5Upgrade to a patched release:
github.com/kubev2v/migration-planner 0.13.5Connected by shared product, vendor, weakness, or advisory.
CVE-2026-53474Critical· 9.6Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands
CVE-2026-53470Critical· 9.6Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs
CVE-2026-53471Critical· 9.6Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation
CVE-2026-53475Critical· 9.3Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication
CVE-2026-53476Critical· 9.6Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution