CVE-2026-71298

Summary

A flaw was found in maestro. A remote attacker could exploit a SQL injection vulnerability in the orderBy query parameter of its REST API list endpoints. This flaw, which does not require authentication, allows for read-only blind extraction of data from the database.

Affected Software

VendorProductVersion RangeStatus

Weaknesses

  • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Workarounds

To mitigate this vulnerability, restrict network access to the maestro REST API list endpoints to trusted clients only. Implement firewall rules or network segmentation to limit exposure of the affected service. If the maestro service is not essential, consider disabling it.

References