Description
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic.
Published: 2026-07-20
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Konnectivity proxy‑server was configured to start its agent‑facing listener without requiring a cluster CA certificate or token‑based authentication, which means client certificates were not validated. This flaw allows a remote attacker who can reach the Konnectivity cluster endpoint to connect as an unauthenticated agent, join the routing pool, and gain a path through which control‑plane‑to‑node traffic can be proxied, inspected, modified, or dropped. The vulnerability is identified as CWE‑306, Improper Authentication.

Affected Systems

Red Hat products affected include Red Hat OpenShift Container Platform 4, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Logging Subsystem for Red Hat OpenShift, Red Hat Multicluster Engine for Kubernetes (including version 2.10), and Red Hat OpenShift API for Data Protection. Specific versions are not enumerated, so any deployment using the affected components with the Konnectivity plugin may be vulnerable.

Risk and Exploitability

The CVSS score of 9.4 classifies the vulnerability as critical, while the EPSS score of less than 1 % indicates a very low likelihood of exploitation in the wild. It is not listed in the CISA KEV catalog. A threat actor who can reach the Konnectivity cluster endpoint can establish an unauthenticated agent session, insert themselves into the routing service, and thereby manipulate traffic between the control plane and cluster nodes. No further impact claims beyond this mechanism are stated in the provided description.

Generated by OpenCVE AI on July 30, 2026 at 19:45 UTC.

Remediation

Vendor Workaround

Until an update that configures Konnectivity agent authentication is applied, restrict network access to the Konnectivity cluster (agent) endpoint so that only trusted worker networks can reach it. For NodePort or LoadBalancer publishing, limit ingress to port 8091 to worker node subnet ranges. For Route-based publishing, restrict access to the Konnectivity route to trusted networks where possible. These controls reduce the chance that an unauthenticated attacker can reach the agent listener; they do not replace proper agent client-certificate (or token) authentication.


OpenCVE Recommended Actions

  • Restrict inbound traffic to the Konnectivity cluster endpoint so that only trusted worker node subnet ranges (or other secure networks) can reach it; for NodePort or LoadBalancer configurations limit access to port 8091, and for Route‑based configurations limit the route to trusted networks (workaround).
  • If the Konnectivity agent listener is not required for your deployment, disable or remove the service to eliminate the vulnerable interface entirely.
  • Continuously monitor Konnectivity logs for unauthorized agent connections and verify that any future updates enforce client‑certificate validation.

Generated by OpenCVE AI on July 30, 2026 at 19:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4.17::el9
References

Wed, 05 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4.18::el9
References

Wed, 05 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4.19::el9
References

Wed, 05 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4.20::el9
cpe:/a:redhat:openshift:4.21::el9
References

Tue, 04 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4.22::el9
References

Sun, 02 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat advanced Cluster Management For Kubernetes
Redhat logging Subsystem For Red Hat Openshift
Redhat multicluster Engine For Kubernetes
Redhat openshift Api For Data Protection
Redhat openshift Container Platform
Vendors & Products Redhat advanced Cluster Management For Kubernetes
Redhat logging Subsystem For Red Hat Openshift
Redhat multicluster Engine For Kubernetes
Redhat openshift Api For Data Protection
Redhat openshift Container Platform

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:multicluster_engine:2.17::el9
References

Wed, 29 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:multicluster_engine:2.11::el9
cpe:/a:redhat:multicluster_engine:2.6::el9
References

Wed, 29 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:multicluster_engine:2.9::el9
References

Wed, 29 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:multicluster_engine:2.8::el9
References

Tue, 28 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
References

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:multicluster_engine:2.10::el9
References

Tue, 21 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Critical


Mon, 20 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic.
Title Hypershift: konnectivity proxy-server accepts agent connections without validating client certificates
First Time appeared Redhat
Redhat acm
Redhat logging
Redhat multicluster Engine
Redhat openshift
Redhat openshift Api Data Protection
Weaknesses CWE-306
CPEs cpe:/a:redhat:acm:2
cpe:/a:redhat:logging:6
cpe:/a:redhat:multicluster_engine
cpe:/a:redhat:openshift:4
cpe:/a:redhat:openshift_api_data_protection:1
Vendors & Products Redhat
Redhat acm
Redhat logging
Redhat multicluster Engine
Redhat openshift
Redhat openshift Api Data Protection
References
Metrics cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}


Subscriptions

Redhat Acm Advanced Cluster Management For Kubernetes Logging Logging Subsystem For Red Hat Openshift Multicluster Engine Multicluster Engine For Kubernetes Openshift Openshift Api Data Protection Openshift Api For Data Protection Openshift Container Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-09T15:54:42.054Z

Reserved: 2026-07-20T05:06:35.638Z

Link: CVE-2026-16242

cve-icon Vulnrichment

Updated: 2026-07-21T14:56:34.993Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Critical

Publid Date: 2026-07-17T00:00:00Z

Links: CVE-2026-16242 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T20:15:13Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function