Description
Subscriber Broken Access Control in Aruba Migration Tool <= 1.0.4 versions.
Published: 2026-10-01
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Access via Broken Access Control
Action: Apply Patch
AI Analysis

Impact

The Aruba Migration Tool WordPress plugin, up through version 1.0.4, contains a broken access control flaw that allows an authenticated user with subscriber role or minimal privileges to perform migration operations originally restricted to higher‑privilege accounts. This flaw permits the user to alter or delete migration data, potentially compromising data integrity and confidentiality by exposing or modifying site content during migration procedures. The weakness is identified as CWE‑862, a classic access control breach. Based on the description, it is inferred that an authenticated subscriber can exploit this flaw.

Affected Systems

Known affected product: Aruba.it Aruba Migration Tool plugin for WordPress, versions up to and including 1.0.4. No specific EOL or patch notes are listed beyond the indication that version 1.0.5 includes the fix.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium to high severity. No EPSS score is available, so the exploitation likelihood cannot be quantified from the data provided; the KEV status is not listed. The likely attack vector is through a WordPress site where the plugin is installed; the flaw can be leveraged by an authenticated user with subscriber role or minimal privileges to send crafted requests to the migration endpoint, bypassing the intended restriction, and carrying out unauthorized migration actions.

Generated by OpenCVE AI on October 1, 2026 at 16:52 UTC.

Remediation

Vendor Solution

Update the WordPress Aruba Migration Tool plugin to the latest available version (at least 1.0.5).


OpenCVE Recommended Actions

  • Update the Aruba Migration Tool plugin to version 1.0.5 or newer.
  • Restrict the migration endpoint to authenticated administrator accounts only, ensuring role‑based access controls are enforced.
  • If migration functionality is not required, consider disabling or uninstalling the plugin to remove the vulnerable code path.

Generated by OpenCVE AI on October 1, 2026 at 16:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
Description Subscriber Broken Access Control in Aruba Migration Tool <= 1.0.4 versions.
Title WordPress Aruba Migration Tool plugin <= 1.0.4 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-01T14:33:57.214Z

Reserved: 2026-09-24T10:23:10.131Z

Link: CVE-2026-97258

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T15:17:37.660

Modified: 2026-10-01T15:17:37.660

Link: CVE-2026-97258

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T17:00:15Z

Weaknesses