CVE-2026-53473
Received
Received - Intake
Cross-Site Scripting in Migration Planner UI App
Publication date: 2026-06-10
Last updated on: 2026-06-10
Assigner: Red Hat, Inc.
Description
Description
A flaw was found in migration-planner-ui-app. An attacker can register a malicious discovery agent with a specially crafted credentialUrl containing JavaScript code. When an organizational user clicks this link in the user interface, the embedded malicious code executes within the user's browser session. This cross-site scripting (XSS) vulnerability allows the attacker to compromise the victim's Red Hat Single Sign-On (SSO) session, potentially leading to unauthorized cross-tenant data access and API actions.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| red_hat | migration_planner_ui_app | * |
| red_hat | red_hat_single_sign_on | * |
| react | react | * |
| react_router_dom | react_router_dom | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-79 | The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. |