Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
To mitigate this issue, ensure that client mTLS is enabled for the Maestro gRPC broker by configuring the `BrokerClientCAFile` parameter. If the gRPC message broker type is not required, avoid enabling it. If the gRPC broker is in use, a restart or service reload may be required after applying the configuration changes.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 05 Oct 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the maestro gRPC broker. This vulnerability allows a remote attacker, with a valid client certificate, to bypass authentication. This bypass enables the attacker to subscribe to other consumers' event streams, leading to unauthorized information disclosure, or to publish forged agent status, which can compromise data integrity. | |
| Title | Maestro: maestro: grpc broker has no auth interceptor and client mtls is optional | |
| First Time appeared |
Redhat
Redhat multicluster Engine |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:/a:redhat:multicluster_engine | |
| Vendors & Products |
Redhat
Redhat multicluster Engine |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-06T14:49:48.215Z
Reserved: 2026-08-05T14:50:01.309Z
Link: CVE-2026-71297
Updated: 2026-10-06T14:43:43.751Z
Status : Awaiting Analysis
Published: 2026-10-05T20:17:25.103
Modified: 2026-10-06T15:17:19.260
Link: CVE-2026-71297
OpenCVE Enrichment
Updated: 2026-10-05T21:45:20Z