CVE-2026-71298: Red Hat Multicluster Engine For Kubernetes
Medium severity, CVSS 6.4. EPSS: 0.3% chance of exploitation in the next 30 days.
A flaw was found in maestro. A remote attacker could exploit a SQL injection vulnerability in the `orderBy` query parameter of its REST API list endpoints. This flaw, which does not require authentication, allows for read-only blind extraction of data from the database.
Affected products
- Red Hat Multicluster Engine For Kubernetes
Published 2026-10-05. Last modified 2026-10-06.