CVE-2026-71298Medium· 6.4▾ SunlitA flaw was found in maestro. A remote attacker could exploit a SQL injection vulnerability in the `orderBy` query parameter of its REST API list endpoints. This flaw, which does not require authentication, allows for read-only blind extr…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A flaw was found in maestro. A remote attacker could exploit a SQL injection vulnerability in the orderBy query parameter of its REST API list endpoints. This flaw, which does not require authentication, allows for read-only blind extraction of data from the database.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-71297Medium· 5.4A flaw was found in the maestro gRPC broker
CVE-2026-71299Medium· 6.5A flaw was found in Maestro
CVE-2026-56097Medium· 6.5A flaw was found in rubygem-katello
CVE-2026-105447Medium· 5.5A flaw was found in Quay
CVE-2026-104030Medium· 5.5A flaw was found in sssd
CVE-2026-104029Low· 3.3A flaw was found in SSSD