CVE-2026-53469: Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API
(updated )
A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sending a DELETE request to the /api/v1/sources route, which lacks proper authorization and filtering. This allows for the destruction of all customer data, including sources, agents, and assessments, leading to a critical loss of availability and integrity across the entire SaaS platform.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-53469 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →