CVE-2026-71297

Summary

A flaw was found in the maestro gRPC broker. This vulnerability allows a remote attacker, with a valid client certificate, to bypass authentication. This bypass enables the attacker to subscribe to other consumers' event streams, leading to unauthorized information disclosure, or to publish forged agent status, which can compromise data integrity.

Affected Software

VendorProductVersion RangeStatus

Weaknesses

  • CWE-306: Missing Authentication for Critical Function

Workarounds

To mitigate this issue, ensure that client mTLS is enabled for the Maestro gRPC broker by configuring the BrokerClientCAFile parameter. If the gRPC message broker type is not required, avoid enabling it. If the gRPC broker is in use, a restart or service reload may be required after applying the configuration changes.

References