CVE-2026-71297Medium· 5.4▾ SunlitA flaw was found in the maestro gRPC broker. This vulnerability allows a remote attacker, with a valid client certificate, to bypass authentication. This bypass enables the attacker to subscribe to other consumers' event streams, leading…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A flaw was found in the maestro gRPC broker. This vulnerability allows a remote attacker, with a valid client certificate, to bypass authentication. This bypass enables the attacker to subscribe to other consumers' event streams, leading to unauthorized information disclosure, or to publish forged agent status, which can compromise data integrity.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-71299Medium· 6.5A flaw was found in Maestro
CVE-2026-71298Medium· 6.4A flaw was found in maestro
CVE-2026-12423High· 7.5A flaw was found in Foreman
CVE-2026-96577High· 7.1A flaw was found in oc-mirror
CVE-2025-12548Critical· 9.0A flaw was found in Eclipse Che che-machine-exec
CVE-2025-5187Medium· 6.7kubernetes: kube-apiserver: Nodes can delete themselves by adding an OwnerReference (CVE-2025-5187)