Security Flaw in Konnectivity Proxy-Server Configuration for OpenShift by Red Hat
CVE-2026-16242

9.4CRITICAL

What is CVE-2026-16242?

A configuration issue was identified in the Konnectivity proxy-server used by hosted control planes in OpenShift. The agent-facing listener operates without properly validating client certificates due to the absence of necessary configurations such as --cluster-ca-cert and token-based authentication. This oversight enables unauthenticated external attackers with access to the Konnectivity cluster endpoint to connect as unauthorized agents, thereby risking exposure to sensitive control-plane-to-node traffic. Such an attacker could potentially manipulate routing pools, leading to data inspection or interception.

References

CVSS V3.1

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Microsoft Security Research (MSRC) (Microsoft) for reporting this issue.
.