CVE-2024-8509: Red Hat Migration Toolkit For Virtualization 2.6
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
A vulnerability was found in Forklift Controller. There is no verification against the authorization header except to ensure it uses bearer authentication. Without an Authorization header and some form of a Bearer token, a 401 error occurs. The presence of a token value provides a 200 response with the requested information.
Affected products
- Red Hat Migration Toolkit For Virtualization 2.6: before 2.6.6-2 (fixed in 2.6.6-2)
Published 2024-09-06. Last modified 2026-06-17.