{"api_version":"1","generated_at":"2026-10-05T21:53:14+00:00","cve":"CVE-2026-71297","urls":{"html":"https://cve.report/CVE-2026-71297","api":"https://cve.report/api/cve/CVE-2026-71297.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-71297","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-71297"},"summary":{"title":"Maestro: maestro: grpc broker has no auth interceptor and client mtls is optional","description":"A flaw was found in the maestro gRPC broker. This vulnerability allows a remote attacker, with a valid client certificate, to bypass authentication. This bypass enables the attacker to subscribe to other consumers' event streams, leading to unauthorized information disclosure, or to publish forged agent status, which can compromise data integrity.","state":"PUBLISHED","assigner":"redhat","published_at":"2026-10-05 20:17:25","updated_at":"2026-10-05 20:17:25"},"problem_types":["CWE-306","CWE-306 Missing Authentication for Critical Function"],"metrics":[{"version":"3.1","source":"secalert@redhat.com","type":"Primary","score":"5.4","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"5.4","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","version":"3.1"}}],"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2511518","name":"https://bugzilla.redhat.com/show_bug.cgi?id=2511518","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/security/cve/CVE-2026-71297","name":"https://access.redhat.com/security/cve/CVE-2026-71297","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-71297","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71297","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Red Hat","product":"Multicluster Engine for Kubernetes","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Multicluster Engine for Kubernetes","version":"","platforms":[]}],"timeline":[{"source":"CNA","time":"2026-08-05T00:00:00.000Z","lang":"en","value":"Reported to Red Hat."},{"source":"CNA","time":"2026-10-05T18:00:00.000Z","lang":"en","value":"Made public."}],"solutions":[],"workarounds":[{"source":"CNA","title":"","value":"To mitigate this issue, ensure that client mTLS is enabled for the Maestro gRPC broker by configuring the `BrokerClientCAFile` parameter. If the gRPC message broker type is not required, avoid enabling it. If the gRPC broker is in use, a restart or service reload may be required after applying the configuration changes.","time":"","lang":"en"}],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:multicluster_engine"],"defaultStatus":"affected","packageName":"multicluster-engine/cloudevents-conductor-rhel9","product":"Multicluster Engine for Kubernetes","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:multicluster_engine"],"defaultStatus":"affected","packageName":"multicluster-engine/maestro-rhel9","product":"Multicluster Engine for Kubernetes","vendor":"Red Hat"}],"datePublic":"2026-10-05T18:00:00.000Z","descriptions":[{"lang":"en","value":"A flaw was found in the maestro gRPC broker. This vulnerability allows a remote attacker, with a valid client certificate, to bypass authentication. This bypass enables the attacker to subscribe to other consumers' event streams, leading to unauthorized information disclosure, or to publish forged agent status, which can compromise data integrity."}],"metrics":[{"other":{"content":{"namespace":"https://access.redhat.com/security/updates/classification/","value":"Moderate"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","version":"3.1"},"format":"CVSS"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-306","description":"Missing Authentication for Critical Function","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-05T19:55:49.523Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["vdb-entry","x_refsource_REDHAT"],"url":"https://access.redhat.com/security/cve/CVE-2026-71297"},{"name":"RHBZ#2511518","tags":["issue-tracking","x_refsource_REDHAT"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2511518"}],"timeline":[{"lang":"en","time":"2026-08-05T00:00:00.000Z","value":"Reported to Red Hat."},{"lang":"en","time":"2026-10-05T18:00:00.000Z","value":"Made public."}],"title":"Maestro: maestro: grpc broker has no auth interceptor and client mtls is optional","workarounds":[{"lang":"en","value":"To mitigate this issue, ensure that client mTLS is enabled for the Maestro gRPC broker by configuring the `BrokerClientCAFile` parameter. If the gRPC message broker type is not required, avoid enabling it. If the gRPC broker is in use, a restart or service reload may be required after applying the configuration changes."}],"x_generator":{"engine":"cvelib 1.8.0"},"x_redhatCweChain":"CWE-306: Missing Authentication for Critical Function"}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2026-71297","datePublished":"2026-10-05T19:55:49.523Z","dateReserved":"2026-08-05T14:50:01.309Z","dateUpdated":"2026-10-05T19:55:49.523Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-05 20:17:25","lastModifiedDate":"2026-10-05 20:17:25","problem_types":["CWE-306","CWE-306 Missing Authentication for Critical Function"],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.5}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"71297","Ordinal":"1","Title":"Maestro: maestro: grpc broker has no auth interceptor and client","CVE":"CVE-2026-71297","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"71297","Ordinal":"1","NoteData":"A flaw was found in the maestro gRPC broker. This vulnerability allows a remote attacker, with a valid client certificate, to bypass authentication. This bypass enables the attacker to subscribe to other consumers' event streams, leading to unauthorized information disclosure, or to publish forged agent status, which can compromise data integrity.","Type":"Description","Title":"Maestro: maestro: grpc broker has no auth interceptor and client"}]}}}