{"id":"CVE-2026-71298","title":"A flaw was found in maestro","summary":"A flaw was found in maestro. A remote attacker could exploit a SQL injection vulnerability in the `orderBy` query parameter of its REST API list endpoints. This flaw, which does not require authentication, allows for read-only blind extr…","severity":"medium","cvss":6.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L","cwe":["CWE-89"],"vendor":"Red Hat","product":"multicluster-engine/cloudevents-conductor-rhel9","affected":["multicluster-engine/cloudevents-conductor-rhel9 (all versions)","multicluster-engine/maestro-rhel9 (all versions)"],"published":"2026-10-05","updated":"2026-10-05","sourceUpdated":"2026-10-05T20:17:25.267","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-71298","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-71298","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2511519","label":"secalert@redhat.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-05T19:30:59.997Z","slug":"CVE-2026-71298","body":"## Overview\n\nA flaw was found in maestro. A remote attacker could exploit a SQL injection vulnerability in the `orderBy` query parameter of its REST API list endpoints. This flaw, which does not require authentication, allows for read-only blind extraction of data from the database.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":35.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}