---
id: CVE-2026-71297
title: A flaw was found in the maestro gRPC broker
summary: >-
  A flaw was found in the maestro gRPC broker. This vulnerability allows a
  remote attacker, with a valid client certificate, to bypass authentication.
  This bypass enables the attacker to subscribe to other consumers' event
  streams, leading…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-306
vendor: Red Hat
product: multicluster-engine/cloudevents-conductor-rhel9
affected:
  - multicluster-engine/cloudevents-conductor-rhel9 (all versions)
  - multicluster-engine/maestro-rhel9 (all versions)
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T20:17:25.103'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-71297'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2026-71297'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2511518'
    label: secalert@redhat.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-05T20:32:56.654Z'
---

## Overview

A flaw was found in the maestro gRPC broker. This vulnerability allows a remote attacker, with a valid client certificate, to bypass authentication. This bypass enables the attacker to subscribe to other consumers' event streams, leading to unauthorized information disclosure, or to publish forged agent status, which can compromise data integrity.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
