---
id: CVE-2026-16242
title: >-
  A flaw was found in the Konnectivity proxy-server configuration for hosted
  control planes
summary: >-
  A flaw was found in the Konnectivity proxy-server configuration for hosted
  control planes. The agent-facing listener was started without
  --cluster-ca-cert (and without token-based agent authentication), so client
  certificates were not va…
severity: critical
cvss: 9.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'
cwe:
  - CWE-306
vendor: Red Hat
product: multicluster-engine/hypershift-rhel9-operator
affected:
  - multicluster-engine/hypershift-rhel9-operator (all versions)
  - multicluster-engine/hypershift-rhel9-operator (all versions)
  - multicluster-engine/hypershift-rhel9-operator (all versions)
  - multicluster-engine/hypershift-rhel9-operator (all versions)
  - multicluster-engine/hypershift-rhel9-operator (all versions)
  - multicluster-engine/hypershift-rhel9-operator (all versions)
  - multicluster-engine/hypershift-rhel9-operator (all versions)
  - openshift4/ose-hypershift-rhel8 (all versions)
  - openshift4/ose-hypershift-rhel9 (all versions)
  - openshift4/ose-hypershift-rhel9 (all versions)
  - openshift4/ose-hypershift-rhel9 (all versions)
  - openshift4/ose-hypershift-rhel9 (all versions)
  - openshift4/ose-hypershift-rhel9 (all versions)
  - openshift4/ose-hypershift-rhel9 (all versions)
  - openshift4/ose-hypershift-rhel9 (all versions)
  - openshift4/ose-hypershift-rhel9 (all versions)
  - openshift-logging/cluster-logging-rhel9-operator
  - multicluster-engine/cluster-curator-controller-rhel9
  - multicluster-engine/hypershift-addon-rhel9-operator
  - multicluster-engine/hypershift-cli-rhel9
  - multicluster-engine/managedcluster-import-controller-rhel9
  - oadp/oadp-hypershift-velero-plugin-rhel9
  - oadp/oadp-rhel9-operator
  - rhacm2/acm-multicluster-observability-addon-rhel9
  - rhacm2/acm-must-gather-rhel9
  - rhacm2/endpoint-monitoring-rhel9-operator
  - rhacm2/grafana-dashboard-loader-rhel9
  - rhacm2/metrics-collector-rhel9
  - rhacm2/multicluster-observability-rhel9-operator
  - rhacm2/rbac-query-proxy-rhel9
  - openshift4/ose-aws-ebs-csi-driver-rhel9-operator
  - openshift4/ose-aws-efs-csi-driver-rhel9-operator
  - openshift4/ose-azure-disk-csi-driver-rhel9-operator
  - openshift4/ose-azure-file-csi-driver-operator-rhel9
  - openshift4/ose-cluster-csi-snapshot-controller-rhel9-operator
  - openshift4/ose-cluster-network-operator
  - openshift4/ose-cluster-network-rhel9-operator
  - openshift4/ose-cluster-node-tuning-rhel9-operator
  - openshift4/ose-cluster-storage-rhel9-operator
  - openshift4/ose-csi-driver-manila-rhel9-operator
  - openshift4/ose-openstack-cinder-csi-driver-rhel9-operator
  - openshift4/ose-powervs-block-csi-driver-rhel9-operator
  - openshift4/ose-smb-csi-driver-rhel9-operator
published: '2026-07-20'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T15:17:04.540'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-16242'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:46885'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:47388'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:47728'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:47735'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:47949'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:47953'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:47974'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:48284'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:48657'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:48670'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:48676'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:48693'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:48699'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:50758'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:56789'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:56912'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-16242'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2502690'
    label: secalert@redhat.com
  - url: 'https://github.com/openshift/hypershift/pull/9031'
    label: secalert@redhat.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-07-21T14:56:23.371685Z'
epss: 0.00918
epssPercentile: 0.58575
ingestedAt: '2026-08-02T12:18:23.811Z'
---

## Overview

A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
