Security Flaw in Konnectivity Proxy-Server Configuration for OpenShift by Red Hat
CVE-2026-16242

9.4CRITICAL

What is CVE-2026-16242?

A configuration issue was identified in the Konnectivity proxy-server used by hosted control planes in OpenShift. The agent-facing listener operates without properly validating client certificates due to the absence of necessary configurations such as --cluster-ca-cert and token-based authentication. This oversight enables unauthenticated external attackers with access to the Konnectivity cluster endpoint to connect as unauthorized agents, thereby risking exposure to sensitive control-plane-to-node traffic. Such an attacker could potentially manipulate routing pools, leading to data inspection or interception.

Affected Version(s)

multicluster engine for Kubernetes 2.1 1784905766

multicluster engine for Kubernetes 2.1 1784905766

multicluster engine for Kubernetes 2.11.0 1784945966

References

CVSS V3.1

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Microsoft Security Research (MSRC) (Microsoft) for reporting this issue.
.