A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic.
History

Mon, 20 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Critical


Mon, 20 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic.
Title Hypershift: konnectivity proxy-server accepts agent connections without validating client certificates
First Time appeared Redhat
Redhat acm
Redhat logging
Redhat multicluster Engine
Redhat openshift
Redhat openshift Api Data Protection
Weaknesses CWE-306
CPEs cpe:/a:redhat:acm:2
cpe:/a:redhat:logging:6
cpe:/a:redhat:multicluster_engine
cpe:/a:redhat:openshift:4
cpe:/a:redhat:openshift_api_data_protection:1
Vendors & Products Redhat
Redhat acm
Redhat logging
Redhat multicluster Engine
Redhat openshift
Redhat openshift Api Data Protection
References
Metrics cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-07-20T16:46:34.163Z

Reserved: 2026-07-20T05:06:35.638Z

Link: CVE-2026-16242

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

Severity : Critical

Publid Date: 2026-07-17T00:00:00Z

Links: CVE-2026-16242 - Bugzilla

cve-icon OpenCVE Enrichment

No data.