CVE-2026-71299

Summary

A flaw was found in Maestro. Its REST API write endpoints were registered without proper authentication middleware. This allows a remote attacker to perform unauthorized write operations, such as creating, modifying, or deleting consumers and resource bundles. This could lead to data integrity issues or a denial of service (DoS).

Affected Software

VendorProductVersion RangeStatus

Weaknesses

  • CWE-306: Missing Authentication for Critical Function

Workarounds

To mitigate this issue, disable the OpenShift Route for the Maestro component if external authentication is not configured. This can be achieved by setting route.enabled=false in the Maestro Helm chart configuration. Alternatively, implement an external authentication layer, such as an Istio AuthorizationPolicy, NetworkPolicy, or oauth-proxy, to secure the exposed REST API endpoints. Disabling the route may impact functionality that relies on external access to Maestro's REST API.

References