No analysis available yet.
Vendor Workaround
To mitigate this issue, ensure that client mTLS is enabled for the Maestro gRPC broker by configuring the `BrokerClientCAFile` parameter. If the gRPC message broker type is not required, avoid enabling it. If the gRPC broker is in use, a restart or service reload may be required after applying the configuration changes.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the maestro gRPC broker. This vulnerability allows a remote attacker, with a valid client certificate, to bypass authentication. This bypass enables the attacker to subscribe to other consumers' event streams, leading to unauthorized information disclosure, or to publish forged agent status, which can compromise data integrity. | |
| Title | Maestro: maestro: grpc broker has no auth interceptor and client mtls is optional | |
| First Time appeared |
Redhat
Redhat multicluster Engine |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:/a:redhat:multicluster_engine | |
| Vendors & Products |
Redhat
Redhat multicluster Engine |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-05T19:55:49.523Z
Reserved: 2026-08-05T14:50:01.309Z
Link: CVE-2026-71297
No data.
Status : Received
Published: 2026-10-05T20:17:25.103
Modified: 2026-10-05T20:17:25.103
Link: CVE-2026-71297
No data.
OpenCVE Enrichment
No data.
-
CWE-306
Missing Authentication for Critical Function