Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-16242: OpenShift Konnectivity proxy allows unauthenticated access
CVE-2026-16242 · published 2 months ago
Summary
The Konnectivity proxy used in Red Hat OpenShift Container Platform (versions 4.2 through 4.17) and related OpenShift components was configured without proper certificate checking. This lets anyone who can reach the proxy endpoint join the network and see or change traffic between the control plane and worker nodes. Apply the vendor's configuration update or patch to require certificate validation and token authentication for agents.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| red hat | red hat openshift container platform 4.2 | All versions |
| red hat | red hat openshift container platform 4.17 | All versions |
| red hat | logging subsystem for red hat openshift | All versions |
| red hat | multicluster engine for kubernetes | All versions |
| red hat | openshift api for data protection | All versions |
| red hat | red hat advanced cluster management for kubernetes 2 | All versions |
| red hat | red hat openshift container platform 4 | All versions |
| red hat | multicluster engine for kubernetes 2.10 | All versions |
| red hat | multicluster engine for kubernetes 2.8 | All versions |
| red hat | multicluster engine for kubernetes 2.9 | All versions |
| red hat | multicluster engine for kubernetes 2.1 | All versions |
| red hat | multicluster engine for kubernetes 2.11 | All versions |
| red hat | multicluster engine for kubernetes 2.17 | All versions |
| red hat | multicluster engine for kubernetes 2.6 | All versions |
| red hat | multicluster engine for kubernetes 2.11.0 | All versions |
| red hat | red hat openshift container platform 4.22 | All versions |
| red hat | red hat openshift container platform 4.20 | All versions |
| red hat | red hat openshift container platform 4.21 | All versions |
| red hat | red hat openshift container platform 4.19 | All versions |
| red hat | red hat openshift container platform 4.18 | All versions |
| red hat | multicluster engine for kubernetes 2.9.0 | All versions |
| red hat | red hat openshift container platform 4.16 | All versions |
| red hat | red hat openshift container platform 4.14 | All versions |
| red hat | red hat openshift container platform 4.15 | All versions |
Original advisory text
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authenticat...
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic.
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2502690
- https://github.com/openshift/hypershift/pull/9031
- https://access.redhat.com/errata/RHSA-2026:56912
- https://access.redhat.com/errata/RHSA-2026:47735
- https://access.redhat.com/errata/RHSA-2026:47953
- https://access.redhat.com/errata/RHSA-2026:47949
- https://access.redhat.com/errata/RHSA-2026:46885
- https://access.redhat.com/errata/RHSA-2026:47388
- https://access.redhat.com/errata/RHSA-2026:47728
- https://access.redhat.com/errata/RHSA-2026:47974
- https://access.redhat.com/errata/RHSA-2026:48284
- https://access.redhat.com/errata/RHSA-2026:48657
- https://access.redhat.com/errata/RHSA-2026:48670
- https://access.redhat.com/errata/RHSA-2026:48676
- https://access.redhat.com/errata/RHSA-2026:48693
- https://access.redhat.com/errata/RHSA-2026:48699
- https://access.redhat.com/errata/RHSA-2026:50758
- https://access.redhat.com/errata/RHSA-2026:56789
- https://access.redhat.com/security/cve/CVE-2026-16242
Severity
9.4
Critical
CVSS 3.1: 9.4 (NVD)
Exploitation
EPSS <1%
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published20 Jul 2026
Updated27 Sep 2026
First seen20 Jul 2026
Track software like this
Free during beta