{
  "id": "CVE-2026-71297",
  "url": "https://spydr.io/cve/CVE-2026-71297",
  "published": "2026-10-05T20:17:25.103Z",
  "modified": "2026-10-05T20:17:25.103Z",
  "score": 5.4,
  "severity": "medium",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
  "score_source": "redhat.com",
  "epss": null,
  "epss_percentile": null,
  "exploited": false,
  "kev": null,
  "ssvc_exploitation": null,
  "vendors": [
    "Red Hat"
  ],
  "products": [
    "Red Hat Multicluster Engine for Kubernetes"
  ],
  "cwes": [
    "CWE-306"
  ],
  "description": "A flaw was found in the maestro gRPC broker. This vulnerability allows a remote attacker, with a valid client certificate, to bypass authentication. This bypass enables the attacker to subscribe to other consumers' event streams, leading to unauthorized information disclosure, or to publish forged agent status, which can compromise data integrity.",
  "status": "Received",
  "score_type": "Primary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 5.4,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "https://access.redhat.com/security/cve/CVE-2026-71297",
      "tags": []
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2511518",
      "tags": []
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-71297",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
