AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-53472

MEDIUM · CVSS 6.3

Source: NVD + CISA KEV + EPSS · Published 2026-08-14 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

A vulnerability in the migration-planner component of Java allows authenticated attackers to exploit insufficient validation of the `AgentStatusUpdate.CredentialUrl` field, enabling them to store a malicious `javascript:` URL. This can lead to Cross-Site Scripting (XSS) when victims access the Hybrid Cloud Console, potentially compromising sensitive information through script execution in their sessions. Organizations using this Java component, particularly those with hybrid cloud environments, should prioritize remediation to mitigate the risk of XSS attacks.

CVE
CVE-2026-53472
Severity
MEDIUM
CVSS
6.3
EPSS
N/A
Java

Original NVD Description

A flaw was found in migration-planner. Insufficient validation of the `AgentStatusUpdate.CredentialUrl` field allows an authenticated attacker to store a malicious `javascript:` URL. When a victim views this URL in the Hybrid Cloud Console, it can lead to Cross-Site Scripting (XSS), enabling script execution in the victim's session and potentially disclosing sensitive information.