HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-53473Published Modified CNA redhat

CVE-2026-53473: Migration-planner-ui-app: stored xss via javascript: url in agent credential link

A flaw was found in migration-planner-ui-app. An attacker can register a malicious discovery agent with a specially crafted credentialUrl containing JavaScript code. When an organizational user clicks this link in the user interface, the embedded malicious code executes within the user's browser session. This cross-site scripting (XSS) vulnerability allows the attacker to compromise the victim's Red Hat Single Sign-On (SSO) session, potentially leading to unauthorized cross-tenant data access and API actions.

Metrics

CVSS v3.1
7.3
Severity
HIGH
Fixed in
0.13.5
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

Stored cross-site scripting (XSS) in migration-planner-ui-app allows an attacker who can register a discovery agent to plant a malicious JavaScript URL in the credentialUrl field. When a legitimate user clicks that link in the migration planner UI, the injected code runs in their browser session. Successful exploitation gives the attacker control of the victim's Red Hat Single Sign-On (SSO) session, enabling unauthorized reads and writes across tenant boundaries. A patched-image rebuild at version 0.13.5 is available on HarborGuard for affected environments.

HarborGuard Coverage

Detection

Detection for CVE-2026-53473 is available across every HarborGuard environment; the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that bundle migration-planner-ui-app at a version below 0.13.5.

Available
Triage

HarborGuard is capable of scoring this CVE at CVSS 7.3 HIGH and weighting that score against each environment's compliance policy to surface it at the correct severity tier. Per-organization routing rules can direct the finding to the appropriate team inbox automatically.

Available
Patch

A patched-image rebuild at version 0.13.5 is available on HarborGuard for any environment running an affected image. For customers who opt into auto-remediation, HarborGuard can trigger the rebuild, run a regression test suite against it, and open a PR against affected workloads without manual intervention.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the migration-planner-ui-app service over the network to register a malicious agent and the victim must access the UI over the network for the payload to fire.

  • AuthenticationRequired

    The attacker needs at least a low-privilege account to register a discovery agent with a crafted credentialUrl; any authenticated user with agent-registration access is sufficient.

  • Victim interactionRequired

    A legitimate organizational user must click the malicious credentialUrl link in the migration planner UI for the injected JavaScript to execute.

  • Attack complexityDetail

    Attack complexity is low; the exploit is reliable and requires no race conditions or special environmental configuration beyond registering the malicious agent and waiting for a user click.

Blast Radius

  • The attacker reads the victim's active Red Hat Single Sign-On session token, enabling impersonation of that user.
  • With a captured session, the attacker can issue API calls as the victim, including reads of data belonging to other tenants in a shared deployment.
  • The attacker can perform write-level API actions (creating, modifying, or deleting migration plans and associated resources) under the victim's identity.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-53473 activates as soon as the CVE is ingested, and any image containing migration-planner-ui-app below version 0.13.5 is flagged HIGH in the matching environment's finding queue. A patched-image rebuild at 0.13.5 is available for affected images; for customers who opt into auto-remediation, HarborGuard can execute the full rebuild-and-PR flow (rebuild, regression run, PR opened against affected workloads) with a median time from CVE publication to merged patch PR of around 90 minutes for high-severity issues in environments with auto-remediation enabled. Where compliance policy does not permit auto-remediation, the finding is routed to the designated team inbox with CVSS score, affected image list, and fix-version guidance so the team can act manually. Until an upgrade is applied, compensating controls such as network-policy restrictions on who can register discovery agents and UI-layer input validation on credentialUrl fields can reduce exposure.

See how HarborGuard automates this

Fix available

0.13.5
Affected packages
  • unknown
    < 0.13.5 (from 0)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N