Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Until an update that configures Konnectivity agent authentication is applied, restrict network access to the Konnectivity cluster (agent) endpoint so that only trusted worker networks can reach it. For NodePort or LoadBalancer publishing, limit ingress to port 8091 to worker node subnet ranges. For Route-based publishing, restrict access to the Konnectivity route to trusted networks where possible. These controls reduce the chance that an unauthenticated attacker can reach the agent listener; they do not replace proper agent client-certificate (or token) authentication.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 21 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Jul 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 20 Jul 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic. | |
| Title | Hypershift: konnectivity proxy-server accepts agent connections without validating client certificates | |
| First Time appeared |
Redhat
Redhat acm Redhat logging Redhat multicluster Engine Redhat openshift Redhat openshift Api Data Protection |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:/a:redhat:acm:2 cpe:/a:redhat:logging:6 cpe:/a:redhat:multicluster_engine cpe:/a:redhat:openshift:4 cpe:/a:redhat:openshift_api_data_protection:1 |
|
| Vendors & Products |
Redhat
Redhat acm Redhat logging Redhat multicluster Engine Redhat openshift Redhat openshift Api Data Protection |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-07-21T14:59:44.396Z
Reserved: 2026-07-20T05:06:35.638Z
Link: CVE-2026-16242
Updated: 2026-07-21T14:56:34.993Z
No data.
OpenCVE Enrichment
No data.