CVE-2026-71297mediumCWE-306

CVE-2026-71297: fallo de gravedad media en Red Hat Multicluster Engine for Kubernetes

Maestro: maestro: grpc broker has no auth interceptor and client mtls is optional

Publicada el · Actualizada el

13Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 5.4epss 0.2%
probabilidad de explotación
0.2%top 96% de las CVE
explotación observada
noninguna fuente lo reporta
A flaw was found in the maestro gRPC broker. This vulnerability allows a remote attacker, with a valid client certificate, to bypass authentication. This bypass enables the attacker to subscribe to other consumers' event streams, leading to unauthorized information disclosure, or to publish forged agent status, which can compromise data integrity.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N