Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Until an update that configures Konnectivity agent authentication is applied, restrict network access to the Konnectivity cluster (agent) endpoint so that only trusted worker networks can reach it. For NodePort or LoadBalancer publishing, limit ingress to port 8091 to worker node subnet ranges. For Route-based publishing, restrict access to the Konnectivity route to trusted networks where possible. These controls reduce the chance that an unauthenticated attacker can reach the agent listener; they do not replace proper agent client-certificate (or token) authentication.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 12 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:openshift:4.16::el9 | |
| References |
|
Thu, 06 Aug 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:openshift:4.17::el9 | |
| References |
|
Wed, 05 Aug 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:openshift:4.18::el9 | |
| References |
|
Wed, 05 Aug 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:openshift:4.19::el9 | |
| References |
|
Wed, 05 Aug 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:openshift:4.20::el9 cpe:/a:redhat:openshift:4.21::el9 |
|
| References |
|
Tue, 04 Aug 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:openshift:4.22::el9 | |
| References |
|
Sun, 02 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat advanced Cluster Management For Kubernetes
Redhat logging Subsystem For Red Hat Openshift Redhat multicluster Engine For Kubernetes Redhat openshift Api For Data Protection Redhat openshift Container Platform |
|
| Vendors & Products |
Redhat advanced Cluster Management For Kubernetes
Redhat logging Subsystem For Red Hat Openshift Redhat multicluster Engine For Kubernetes Redhat openshift Api For Data Protection Redhat openshift Container Platform |
Thu, 30 Jul 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:multicluster_engine:2.17::el9 | |
| References |
|
Wed, 29 Jul 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:multicluster_engine:2.11::el9 cpe:/a:redhat:multicluster_engine:2.6::el9 |
|
| References |
|
Wed, 29 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:multicluster_engine:2.9::el9 | |
| References |
|
Wed, 29 Jul 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:multicluster_engine:2.8::el9 | |
| References |
|
Tue, 28 Jul 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 27 Jul 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:multicluster_engine:2.10::el9 | |
| References |
|
Tue, 21 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Jul 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 20 Jul 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic. | |
| Title | Hypershift: konnectivity proxy-server accepts agent connections without validating client certificates | |
| First Time appeared |
Redhat
Redhat acm Redhat logging Redhat multicluster Engine Redhat openshift Redhat openshift Api Data Protection |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:/a:redhat:acm:2 cpe:/a:redhat:logging:6 cpe:/a:redhat:multicluster_engine cpe:/a:redhat:openshift:4 cpe:/a:redhat:openshift_api_data_protection:1 |
|
| Vendors & Products |
Redhat
Redhat acm Redhat logging Redhat multicluster Engine Redhat openshift Redhat openshift Api Data Protection |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-12T20:50:49.722Z
Reserved: 2026-07-20T05:06:35.638Z
Link: CVE-2026-16242
Updated: 2026-07-21T14:56:34.993Z
Status : Awaiting Analysis
Published: 2026-07-20T08:16:29.833
Modified: 2026-08-12T21:17:36.000
Link: CVE-2026-16242
OpenCVE Enrichment
Updated: 2026-08-02T20:15:13Z