Authentication Bypass Vulnerability in Maestro gRPC Broker by Red Hat
CVE-2026-71297

5.4MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
5 October 2026

What is CVE-2026-71297?

A flaw has been identified in the Maestro gRPC Broker that could enable a remote attacker, armed with a valid client certificate, to circumvent authentication protections. This vulnerability allows unauthorized access to other consumers' event streams, potentially leading to the disclosure of sensitive information and the ability to publish altered agent status updates, which jeopardizes the integrity of data within the system.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.