CVE-2026-53476: assisted-migration-agent: VDDK Tarball Chained-Symlink Arbitrary File Write

Severity: Critical

CVSS Score: 9.6

A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN), can exploit a path traversal vulnerability. By crafting a specially designed gzipped tarball, the attacker can bypass security checks and write arbitrary files to the system. This could ultimately lead to the execution of unauthorized code on the appliance.