CVE-2026-53469
EUVD-2026-3602810.06.2026, 15:16
A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sending a DELETE request to the /api/v1/sources route, which lacks proper authorization and filtering. This allows for the destruction of all customer data, including sources, agents, and assessments, leading to a critical loss of availability and integrity across the entire SaaS platform.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| kebev2v | migration_assessment | 𝑥 < 0.13.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration