CVE-2026-53469: KEBEV2V Migration Assessment

High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.

A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sending a DELETE request to the /api/v1/sources route, which lacks proper authorization and filtering. This allows for the destruction of all customer data, including sources, agents, and assessments, leading to a critical loss of availability and integrity across the entire SaaS platform.

Affected products

  • KEBEV2V Migration Assessment: before 0.13.5 (fixed in 0.13.5)

Published 2026-06-10. Last modified 2026-06-17.