← All CVEs

CVE-2026-53476

critical · 9.6

A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal vulnerability. By crafting a specially designed gzipped tarball, the attacker can bypass security checks and write arbitrary files to the system. This could ultimately lead to the execution of unauthorized code on the appliance.

9.6
CVSS
0.3%
EPSS (exploit prob.)
22nd
EPSS percentile
2026-06-10
Published

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-59CWE-22

Affected products

VendorProductAffected versions
kubev2vassisted_migration_agent< 2026-06-07

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-53476