Security Flaw in Konnectivity Proxy-Server Configuration for OpenShift by Red Hat
CVE-2026-16242
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 20 July 2026
What is CVE-2026-16242?
A configuration issue was identified in the Konnectivity proxy-server used by hosted control planes in OpenShift. The agent-facing listener operates without properly validating client certificates due to the absence of necessary configurations such as --cluster-ca-cert and token-based authentication. This oversight enables unauthenticated external attackers with access to the Konnectivity cluster endpoint to connect as unauthorized agents, thereby risking exposure to sensitive control-plane-to-node traffic. Such an attacker could potentially manipulate routing pools, leading to data inspection or interception.
Affected Version(s)
multicluster engine for Kubernetes 2.1 1784905766
multicluster engine for Kubernetes 2.1 1784905766
multicluster engine for Kubernetes 2.11.0 1784945966
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved