Description
A flaw was found in the maestro gRPC broker. This vulnerability allows a remote attacker, with a valid client certificate, to bypass authentication. This bypass enables the attacker to subscribe to other consumers' event streams, leading to unauthorized information disclosure, or to publish forged agent status, which can compromise data integrity.
Published: 2026-10-05
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

To mitigate this issue, ensure that client mTLS is enabled for the Maestro gRPC broker by configuring the `BrokerClientCAFile` parameter. If the gRPC message broker type is not required, avoid enabling it. If the gRPC broker is in use, a restart or service reload may be required after applying the configuration changes.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 05 Oct 2026 20:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in the maestro gRPC broker. This vulnerability allows a remote attacker, with a valid client certificate, to bypass authentication. This bypass enables the attacker to subscribe to other consumers' event streams, leading to unauthorized information disclosure, or to publish forged agent status, which can compromise data integrity.
Title Maestro: maestro: grpc broker has no auth interceptor and client mtls is optional
First Time appeared Redhat
Redhat multicluster Engine
Weaknesses CWE-306
CPEs cpe:/a:redhat:multicluster_engine
Vendors & Products Redhat
Redhat multicluster Engine
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Redhat Multicluster Engine
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-06T14:49:48.215Z

Reserved: 2026-08-05T14:50:01.309Z

Link: CVE-2026-71297

cve-icon Vulnrichment

Updated: 2026-10-06T14:43:43.751Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-05T20:17:25.103

Modified: 2026-10-06T15:17:19.260

Link: CVE-2026-71297

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-10-05T18:00:00Z

Links: CVE-2026-71297 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T21:45:20Z

Weaknesses