CVE-2026-71298
6.4
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L
Summary
A flaw was found in maestro. A remote attacker could exploit a SQL injection vulnerability in the orderBy query parameter of its REST API list endpoints. This flaw, which does not require authentication, allows for read-only blind extraction of data from the database.
Affected Software
| Vendor | Product | Version Range | Status |
|---|
Weaknesses
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Workarounds
To mitigate this vulnerability, restrict network access to the maestro REST API list endpoints to trusted clients only. Implement firewall rules or network segmentation to limit exposure of the affected service. If the maestro service is not essential, consider disabling it.
References
- https://access.redhat.com/security/cve/CVE-2026-71298
- https://bugzilla.redhat.com/show_bug.cgi?id=2511519
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.