CVE-2026-73298General

LOWCVSS 8.7 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-driven migration solution for moving container service configurations to Azure Kubernetes Service. In version 2.1.2 and earlier, a security vulnerability was identified in the Container Migration Solution Accelerator, specifically an authenticated IDOR (Insecure Direct Object Reference) that allows users to read, write, and delete processes belonging to other authenticated users. The issue affects multiple API endpoints, where ownership checks are missing, enabling unauthorized access and modification of migration data across users within the same organization. The vulnerability is present in both process and file management APIs, and the application relies on Entra ID authentication but lacks proper authorization controls between users. Authenticated users are able to access, modify, and delete processes and files belonging to other users without proper authorization checks.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-12: 3Technical Details · 2026-08-12: 108-12
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-73298 Authenticated IDOR in Microsoft Container Migration Solution Accelerator Allows Data Access https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-73298

    Post summary

    A concise disclosure of CVE-2026-73298, highlighting an authenticated IDOR in Microsoft Container Migration Solution Accelerator that permits unauthorized data access.

    00000139
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-73298 The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-driven migration solution for moving container s… https://www.cve.org/CVERecord?id=CVE-2026-73298 ----- Traducción: CVE-2026-73298 El … http://infoflow.cloud`

    Post summary

    The post merely references CVE-2026-73298 with a link to its CVE record, lacking specific details about the vulnerability, exploitation status, or fixes.

    0000034
    97 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-73298 The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-driven migration solution for moving container s… https://www.cve.org/CVERecord?id=CVE-2026-73298

    Post summary

    The snippet merely references the CVE and provides a link to its record without detailing the vulnerability or any related PoC, exploit, or patch.

    00000932
    57.9K followersView on X

Explore more