A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic.

Project Subscriptions

Vendors Products
Logging Subscribe
Multicluster Engine Subscribe
Openshift Subscribe
Openshift Api Data Protection Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

Until an update that configures Konnectivity agent authentication is applied, restrict network access to the Konnectivity cluster (agent) endpoint so that only trusted worker networks can reach it. For NodePort or LoadBalancer publishing, limit ingress to port 8091 to worker node subnet ranges. For Route-based publishing, restrict access to the Konnectivity route to trusted networks where possible. These controls reduce the chance that an unauthenticated attacker can reach the agent listener; they do not replace proper agent client-certificate (or token) authentication.

History

Mon, 20 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Critical


Mon, 20 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic.
Title Hypershift: konnectivity proxy-server accepts agent connections without validating client certificates
First Time appeared Redhat
Redhat acm
Redhat logging
Redhat multicluster Engine
Redhat openshift
Redhat openshift Api Data Protection
Weaknesses CWE-306
CPEs cpe:/a:redhat:acm:2
cpe:/a:redhat:logging:6
cpe:/a:redhat:multicluster_engine
cpe:/a:redhat:openshift:4
cpe:/a:redhat:openshift_api_data_protection:1
Vendors & Products Redhat
Redhat acm
Redhat logging
Redhat multicluster Engine
Redhat openshift
Redhat openshift Api Data Protection
References
Metrics cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-07-20T16:46:34.163Z

Reserved: 2026-07-20T05:06:35.638Z

Link: CVE-2026-16242

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Critical

Publid Date: 2026-07-17T00:00:00Z

Links: CVE-2026-16242 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses