Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-16242: Hypershift Konnectivity Proxy Allows Unauthenticated Agent Connections
CVE-2026-16242
CVE-2026-16242
Summary
The Konnectivity proxy-server in Hypershift does not verify the identity of agents connecting to it. This means an attacker who can reach the proxy could connect without being authenticated, and potentially intercept, modify, or block traffic between control planes and nodes. To protect against this, ensure that client certificates are validated when configuring the proxy-server.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| red hat | logging subsystem for red hat openshift | All versions |
| red hat | multicluster engine for kubernetes | All versions |
| red hat | openshift api for data protection | All versions |
| red hat | red hat advanced cluster management for kubernetes 2 | All versions |
| red hat | red hat openshift container platform 4 | All versions |
Original title
Hypershift: konnectivity proxy-server accepts agent connections without validating client certificates
Original description
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic.
nvd CVSS3.1
9.4
Vulnerability type
CWE-306
Missing Authentication for Critical Function
Published: 20 Jul 2026 · Updated: 20 Jul 2026 · First seen: 20 Jul 2026