Retour à la veille

CVE-2026-71297

Publié : 5 octobre 2026
Modifié : 5 octobre 2026
Lien officiel NVD
Score CVSS
5.4
MEDIUM

Description détaillée

A flaw was found in the maestro gRPC broker. This vulnerability allows a remote attacker, with a valid client certificate, to bypass authentication. This bypass enables the attacker to subscribe to other consumers' event streams, leading to unauthorized information disclosure, or to publish forged agent status, which can compromise data integrity.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Références et Patchs