CVE-2026-71297
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Summary
A flaw was found in the maestro gRPC broker. This vulnerability allows a remote attacker, with a valid client certificate, to bypass authentication. This bypass enables the attacker to subscribe to other consumers' event streams, leading to unauthorized information disclosure, or to publish forged agent status, which can compromise data integrity.
Affected Software
| Vendor | Product | Version Range | Status |
|---|
Weaknesses
- CWE-306: Missing Authentication for Critical Function
Workarounds
To mitigate this issue, ensure that client mTLS is enabled for the Maestro gRPC broker by configuring the BrokerClientCAFile parameter. If the gRPC message broker type is not required, avoid enabling it. If the gRPC broker is in use, a restart or service reload may be required after applying the configuration changes.
References
- https://access.redhat.com/security/cve/CVE-2026-71297
- https://bugzilla.redhat.com/show_bug.cgi?id=2511518
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.