Executive brief
The Assisted Migration Agent is a tool used to migrate workloads to vSphere and Kubernetes environments. The application hardcodes insecure TLS connections when communicating with vCenter servers, disabling certificate validation entirely. An attacker positioned on the network (via ARP spoofing, rogue DHCP, or compromised infrastructure) can intercept these connections and steal vCenter administrator credentials, leading to full compromise of the virtualization platform.
Technical details
This vulnerability is a certificate validation bypass (CWE-295) affecting the Assisted Migration Agent version < 0.16.0. The root cause is hardcoded insecure TLS parameters across multiple code paths: soap.NewClient(u, true) in auth.go:78, vmware.NewVsphereClient(ctx, creds, true) in inspector.go:97 and forecaster.go:114/194, and cfg.Insecure = true in rightsizing.go:258. There is no configuration option to provide a CA bundle or enable TLS verification. The attack vector is adjacent network (ARP spoofing, rogue DHCP, compromised switch), requires no privileges or user interaction, and has changed scope. An attacker can intercept vCenter credential exchanges and assume administrative identity. The fix (version 0.16.0) extends the Credentials model with optional CACert and Insecure fields, replaces hardcoded boolean literals with a helper function that properly configures TLS, and defaults to verification enabled when a CA is provided.
Affected products
- kubev2v Assisted Migration Agent < 0.16.0
Timeline
- 2026-06-10: disclosed
- 2026-06-10: patched: Version 0.16.0 released with fix