CVE-2026-71299
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Summary
A flaw was found in Maestro. Its REST API write endpoints were registered without proper authentication middleware. This allows a remote attacker to perform unauthorized write operations, such as creating, modifying, or deleting consumers and resource bundles. This could lead to data integrity issues or a denial of service (DoS).
Affected Software
| Vendor | Product | Version Range | Status |
|---|
Weaknesses
- CWE-306: Missing Authentication for Critical Function
Workarounds
To mitigate this issue, disable the OpenShift Route for the Maestro component if external authentication is not configured. This can be achieved by setting route.enabled=false in the Maestro Helm chart configuration. Alternatively, implement an external authentication layer, such as an Istio AuthorizationPolicy, NetworkPolicy, or oauth-proxy, to secure the exposed REST API endpoints. Disabling the route may impact functionality that relies on external access to Maestro's REST API.
References
- https://access.redhat.com/security/cve/CVE-2026-71299
- https://bugzilla.redhat.com/show_bug.cgi?id=2511520
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.