CVE-2026-53475

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
10/06/2026
Last modified:
16/06/2026

Description

A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Security (TLS) connections when communicating with vCenter. This vulnerability allows a Man-in-the-Middle (MITM) attacker to intercept and harvest vCenter administrator credentials. This can lead to unauthorized access to vCenter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kubev2v:assisted_migration_agent:*:*:*:*:*:*:*:* 2026-06-10 (excluding)