medium · CVSS v3 6.5
CVE-2026-97258
CVE-2026-97258 is a medium-severity broken access control issue in Aruba Migration Tool versions 1.0.4 and earlier. It may allow unauthorize
Overview
CVE-2026-97258 is a medium-severity broken access control issue in Aruba Migration Tool versions 1.0.4 and earlier. It may allow unauthorized access to subscriber-related functionality or data if the tool is exposed or improperly configured. It matters because migration tools can contain sensitive configuration, credentials, or network-management data.
Description
Subscriber Broken Access Control in Aruba Migration Tool <= 1.0.4 versions.
Impact
Confidentiality and integrity may be affected if an unauthorized user can access subscriber data, configuration, or migration workflows. Availability is less likely to be directly impacted unless the tool is used to modify network or subscriber state. Internal administrators, network operations teams, and users of the migration tool are the primary impacted parties. Exposure risk increases if the tool is reachable from untrusted networks or has weak authentication controls.
Remediation
Upgrade Aruba Migration Tool to a vendor-confirmed fixed version if available. Restrict access to the tool to trusted management networks and administrative accounts only. Enforce strong authentication, role-based access control, and least privilege for any accounts that can use the tool. Review and disable unnecessary network exposure, shared credentials, or default accounts. Monitor access logs for unusual use and validate that migration data is protected at rest and in transit.
Risk context
The CVSS v3 score is 6.5, indicating medium severity. No EPSS score is provided, so exploitation likelihood should be assessed based on deployment exposure and vendor guidance. Defenders should treat this as a moderate-priority access-control issue, especially if the tool is internet-facing or used in sensitive migration workflows.
Affected products
- Aruba Migration Tool <= 1.0.4
Scores
- Severity
- medium
- CVSS v2
- 6.8
- CVSS v3
- 6.5
- CVSS v4
- —
- EPSS
- —