SQL Injection Vulnerability in Maestro REST API
CVE-2026-71298

6.4MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
5 October 2026

What is CVE-2026-71298?

A remote attacker can exploit a SQL injection flaw present in the orderBy query parameter of Maestro's REST API list endpoints. This vulnerability does not require authentication, permitting unauthorized individuals to perform read-only blind data extraction from the underlying database, thus exposing sensitive information. It is crucial for users of affected versions to review their security settings and apply necessary mitigations.

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.