CVE-2026-71299
Received Received - Intake

Maestro REST API Unauthenticated Write Operations

Vulnerability report for CVE-2026-71299, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: redhat-SADP

Description

A flaw was found in Maestro. Its REST API write endpoints were registered without proper authentication middleware. This allows a remote attacker to perform unauthorized write operations, such as creating, modifying, or deleting consumers and resource bundles. This could lead to data integrity issues or a denial of service (DoS).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-06
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
red_hat maestro *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-71299 is a flaw in Red Hat's Maestro component where its REST API write endpoints lack proper authentication. This allows remote attackers to perform unauthorized write operations like creating, modifying, or deleting consumers and resource bundles without authentication.

Detection Guidance

Check if Maestro's REST API endpoints are exposed without authentication by inspecting network traffic for unauthenticated POST, PATCH, or DELETE requests to /api/maestro/v1/consumers or /api/maestro/v1/resource-bundles/{id}. Verify if OpenShift Routes for Maestro are enabled and accessible externally.

Impact Analysis

This vulnerability could lead to data integrity issues or a denial of service (DoS) by allowing attackers to modify or delete critical data. It may also enable unauthorized access to sensitive operations depending on the exposed endpoints.

Compliance Impact

This vulnerability could lead to unauthorized modifications or deletions of data, which may violate GDPR's data integrity and security requirements (Article 32) or HIPAA's integrity and availability safeguards. Unauthorized write access to consumer or resource bundle data may result in non-compliance if sensitive information is exposed or altered without proper controls.

Mitigation Strategies

Disable the OpenShift Route for Maestro by setting route.enabled=false in the Helm chart. Alternatively, implement an external authentication layer like Istio AuthorizationPolicy, NetworkPolicy, or oauth-proxy to secure the REST API endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71299. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart