CVE-2026-71297: Red Hat Multicluster Engine For Kubernetes

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

A flaw was found in the maestro gRPC broker. This vulnerability allows a remote attacker, with a valid client certificate, to bypass authentication. This bypass enables the attacker to subscribe to other consumers' event streams, leading to unauthorized information disclosure, or to publish forged agent status, which can compromise data integrity.

Affected products

  • Red Hat Multicluster Engine For Kubernetes

Published 2026-10-05. Last modified 2026-10-06.