No advisories yet.
Solution
No solution given by the vendor.
Workaround
To mitigate this issue, disable the OpenShift Route for the Maestro component if external authentication is not configured. This can be achieved by setting `route.enabled=false` in the Maestro Helm chart configuration. Alternatively, implement an external authentication layer, such as an Istio AuthorizationPolicy, NetworkPolicy, or oauth-proxy, to secure the exposed REST API endpoints. Disabling the route may impact functionality that relies on external access to Maestro's REST API.
Mon, 05 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Maestro. Its REST API write endpoints were registered without proper authentication middleware. This allows a remote attacker to perform unauthorized write operations, such as creating, modifying, or deleting consumers and resource bundles. This could lead to data integrity issues or a denial of service (DoS). | |
| Title | Maestro: maestro: rest api write endpoints registered without authentication middleware | |
| First Time appeared |
Redhat
Redhat multicluster Engine |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:/a:redhat:multicluster_engine | |
| Vendors & Products |
Redhat
Redhat multicluster Engine |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-05T19:06:52.146Z
Reserved: 2026-08-05T14:50:01.309Z
Link: CVE-2026-71299
No data.
Status : Received
Published: 2026-10-05T20:17:25.430
Modified: 2026-10-05T20:17:25.430
Link: CVE-2026-71299
No data.
OpenCVE Enrichment
No data.