CVE-2026-71297: medium-severity vulnerability in Red Hat Multicluster Engine for Kubernetes
Maestro: maestro: grpc broker has no auth interceptor and client mtls is optional
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.4epss 0.2%
exploitation probability
0.2%top 96% of all CVEs
observed exploitation
nono source reports it
A flaw was found in the maestro gRPC broker. This vulnerability allows a remote attacker, with a valid client certificate, to bypass authentication. This bypass enables the attacker to subscribe to other consumers' event streams, leading to unauthorized information disclosure, or to publish forged agent status, which can compromise data integrity.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Affected products
Red Hat · Multicluster Engine for KubernetesRelated CVEs — Red Hat Multicluster Engine for Kubernetes
In the same product, most dangerous first.
CVE-2024-3727HIGHContainers/image: digest type does not guarantee valid typeEPSS 1.3%CVE-2026-16242CRITICALHypershift: konnectivity proxy-server accepts agent connections without validating client certificatesEPSS 0.9%CVE-2024-12401MEDIUMCert-manager: potential dos when parsing specially crafted pem inputsEPSS 0.7%CVE-2025-2241HIGHHive: exposure of vcenter credentials via clusterprovision in hive / mce / acmEPSS 0.5%CVE-2026-101919HIGHHypershift: hypershift: unsanitized kubeconfig passthrough from tenant namespace to control planeEPSS 0.4%CVE-2026-71299MEDIUMMaestro: maestro: rest api write endpoints registered without authentication middlewareEPSS 0.3%