CVE-2026-71297: falha de média gravidade em Red Hat Multicluster Engine for Kubernetes
Maestro: maestro: grpc broker has no auth interceptor and client mtls is optional
Publicada em · Atualizada em
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 5.4epss 0.2%
probabilidade de exploração
0.2%top 96% das CVEs
exploração observada
nãonenhuma fonte reporta
A flaw was found in the maestro gRPC broker. This vulnerability allows a remote attacker, with a valid client certificate, to bypass authentication. This bypass enables the attacker to subscribe to other consumers' event streams, leading to unauthorized information disclosure, or to publish forged agent status, which can compromise data integrity.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Produtos afetados
Red Hat · Multicluster Engine for KubernetesCVEs relacionadas — Red Hat Multicluster Engine for Kubernetes
No mesmo produto, das mais perigosas para as menos.
CVE-2024-3727HIGHContainers/image: digest type does not guarantee valid typeEPSS 1.3%CVE-2026-16242CRITICALHypershift: konnectivity proxy-server accepts agent connections without validating client certificatesEPSS 0.9%CVE-2024-12401MEDIUMCert-manager: potential dos when parsing specially crafted pem inputsEPSS 0.7%CVE-2025-2241HIGHHive: exposure of vcenter credentials via clusterprovision in hive / mce / acmEPSS 0.5%CVE-2026-101919HIGHHypershift: hypershift: unsanitized kubeconfig passthrough from tenant namespace to control planeEPSS 0.4%CVE-2026-71299MEDIUMMaestro: maestro: rest api write endpoints registered without authentication middlewareEPSS 0.3%