Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-16242: OpenShift Konnectivity proxy allows unauthenticated access

CVE-2026-16242 · published 2 months ago
Summary

The Konnectivity proxy used in Red Hat OpenShift Container Platform (versions 4.2 through 4.17) and related OpenShift components was configured without proper certificate checking. This lets anyone who can reach the proxy endpoint join the network and see or change traffic between the control plane and worker nodes. Apply the vendor's configuration update or patch to require certificate validation and token authentication for agents.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
red hat red hat openshift container platform 4.2 All versions
red hat red hat openshift container platform 4.17 All versions
red hat logging subsystem for red hat openshift All versions
red hat multicluster engine for kubernetes All versions
red hat openshift api for data protection All versions
red hat red hat advanced cluster management for kubernetes 2 All versions
red hat red hat openshift container platform 4 All versions
red hat multicluster engine for kubernetes 2.10 All versions
red hat multicluster engine for kubernetes 2.8 All versions
red hat multicluster engine for kubernetes 2.9 All versions
red hat multicluster engine for kubernetes 2.1 All versions
red hat multicluster engine for kubernetes 2.11 All versions
red hat multicluster engine for kubernetes 2.17 All versions
red hat multicluster engine for kubernetes 2.6 All versions
red hat multicluster engine for kubernetes 2.11.0 All versions
red hat red hat openshift container platform 4.22 All versions
red hat red hat openshift container platform 4.20 All versions
red hat red hat openshift container platform 4.21 All versions
red hat red hat openshift container platform 4.19 All versions
red hat red hat openshift container platform 4.18 All versions
red hat multicluster engine for kubernetes 2.9.0 All versions
red hat red hat openshift container platform 4.16 All versions
red hat red hat openshift container platform 4.14 All versions
red hat red hat openshift container platform 4.15 All versions
Original advisory text
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authenticat...
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic.
Severity
9.4 Critical
CVSS 3.1: 9.4 (NVD)
Exploitation
EPSS <1%
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published20 Jul 2026
Updated27 Sep 2026
First seen20 Jul 2026
Sources
CVE-2026-16242 · MITRE
Track software like this
Free during beta