{"id":"CVE-2026-71297","title":"A flaw was found in the maestro gRPC broker","summary":"A flaw was found in the maestro gRPC broker. This vulnerability allows a remote attacker, with a valid client certificate, to bypass authentication. This bypass enables the attacker to subscribe to other consumers' event streams, leading…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","cwe":["CWE-306"],"vendor":"Red Hat","product":"multicluster-engine/cloudevents-conductor-rhel9","affected":["multicluster-engine/cloudevents-conductor-rhel9 (all versions)","multicluster-engine/maestro-rhel9 (all versions)"],"published":"2026-10-05","updated":"2026-10-05","sourceUpdated":"2026-10-05T20:17:25.103","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-71297","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-71297","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2511518","label":"secalert@redhat.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-05T20:32:56.654Z","slug":"CVE-2026-71297","body":"## Overview\n\nA flaw was found in the maestro gRPC broker. This vulnerability allows a remote attacker, with a valid client certificate, to bypass authentication. This bypass enables the attacker to subscribe to other consumers' event streams, leading to unauthorized information disclosure, or to publish forged agent status, which can compromise data integrity.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}