CVE-2026-71297mediumCWE-306

CVE-2026-71297: medium-severity vulnerability in Red Hat Multicluster Engine for Kubernetes

Maestro: maestro: grpc broker has no auth interceptor and client mtls is optional

Published · Updated

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.4epss 0.2%
exploitation probability
0.2%top 96% of all CVEs
observed exploitation
nono source reports it
A flaw was found in the maestro gRPC broker. This vulnerability allows a remote attacker, with a valid client certificate, to bypass authentication. This bypass enables the attacker to subscribe to other consumers' event streams, leading to unauthorized information disclosure, or to publish forged agent status, which can compromise data integrity.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N