CVE-2026-71299
Red Hat Multicluster Engine for Kubernetes
Published 5 Oct 2026 · updated 5 Oct 2026 · Received
6.5 Medium · CVSS 3.1, redhat.com
Description
A flaw was found in Maestro. Its REST API write endpoints were registered without proper authentication middleware. This allows a remote attacker to perform unauthorized write operations, such as creating, modifying, or deleting consumers and resource bundles. This could lead to data integrity issues or a denial of service (DoS).