assisted-migration-agent Hardcodes Insecure TLS to vCenter, Exposing Admin Credentials to MITM (CVE-2026-53475)
critical-cve-against-infra · active
The assisted-migration-agent uses hardcoded insecure TLS settings when connecting to VMware vCenter, allowing a man-in-the-middle attacker to intercept and harvest vCenter administrator credentials. This can lead to unauthorized access to vCenter.
Affected packages
- goassisted-migration-agent