Sceawere
Vulnerability Detail
CVE-2026-71297UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Maestro gRPC Authentication Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 1h ago
- Vendor
- Red Hat
- Product
- Multicluster Engine for Kubernetes
- Attack Type
- Missing Authentication for Critical Function
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw was found in the maestro gRPC broker. This vulnerability allows a remote attacker, with a valid client certificate, to bypass authentication. This bypass enables the attacker to subscribe to other consumers' event streams, leading to unauthorized information disclosure, or to publish forged agent status, which can compromise data integrity.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-10-05T20:17:25.103Z",
"pubdate": "2026-10-05T20:17:25.103Z",
"executiveSummary": "The maestro gRPC broker is susceptible to an authentication bypass vulnerability that permits unauthorized access to sensitive event streams and agent communications. The vulnerability originates from a flaw in the validation logic of the gRPC broker when handling client certificates. Although a valid client certificate is required, the system fails to correctly verify the authorization scope or identity mapping associated with that certificate, allowing an authenticated client to masquerade as an unauthorized consumer or publisher.\nThe impact of this flaw is significant, as it leads to both information disclosure and a compromise of data integrity. An attacker can leverage this bypass to subscribe to private event streams belonging to other consumers, resulting in the unauthorized exfiltration of sensitive telemetry or operational data. Furthermore, the ability to publish forged agent statuses allows an adversary to manipulate the perceived health and state of the system, potentially leading to administrative misdirection or the triggering of downstream automated processes based on fraudulent data. Given the remote exploitability via the gRPC interface, this vulnerability poses a severe risk to environments where maestro handles critical agent communications and data synchronization.",
"technicalDetails": "The vulnerability resides within the authentication and authorization middleware of the maestro gRPC broker. Specifically, the implementation fails to enforce strict mapping between the common name or identity attributes provided in the mTLS client certificate and the corresponding resource ownership requirements for gRPC service methods.\nUnder normal operating conditions, the broker is expected to authenticate the client certificate and verify that the identity holds the necessary permissions to perform operations on specific topics or streams. However, the flaw occurs during the connection or stream establishment phase where the authorization context is improperly initialized or subsequently bypassed. This leads to a scenario where the broker assumes that the presence of any valid, trusted certificate satisfies the requirements for all gRPC operations, regardless of the target resource's access control list (ACL).\nThe attack flow proceeds as follows: First, an attacker establishes a TLS connection to the maestro gRPC broker using a valid client certificate issued by the organization's trusted Certificate Authority (CA). Second, upon successful completion of the TLS handshake, the broker's transport security layer marks the connection as 'authenticated.' Third, when the attacker initiates a gRPC call—such as a 'Subscribe' or 'Publish' RPC—the service implementation fails to perform a secondary, granular verification of the user's identity against the requested resource. Finally, the broker grants access to the requested stream or allows the publication of a message, enabling the attacker to intercept event payloads or inject malicious status updates.\nThis vulnerability effectively collapses the security boundary between distinct clients. Because the gRPC broker does not validate that the subject of the certificate matches the intended owner of the stream, an attacker can specify arbitrary stream identifiers or actor IDs in their gRPC requests. The lack of validation ensures that these requests are processed as legitimate interactions, allowing for unauthorized read access to event streams and unauthorized write access to agent state management functions. The post-exploitation impact includes the full compromise of data confidentiality for stream-based communications and the ability to influence system operations through the injection of fabricated agent telemetry."
}