CVE-2026-71297mediumCWE-306

CVE-2026-71297: falha de média gravidade em Red Hat Multicluster Engine for Kubernetes

Maestro: maestro: grpc broker has no auth interceptor and client mtls is optional

Publicada em · Atualizada em

13Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 5.4epss 0.2%
probabilidade de exploração
0.2%top 96% das CVEs
exploração observada
nãonenhuma fonte reporta
A flaw was found in the maestro gRPC broker. This vulnerability allows a remote attacker, with a valid client certificate, to bypass authentication. This bypass enables the attacker to subscribe to other consumers' event streams, leading to unauthorized information disclosure, or to publish forged agent status, which can compromise data integrity.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N