LiveActive security incident?Get immediate response
CVE Record

CVE-2026-16242: Hypershift: konnectivity proxy-server accepts agent connections without validating client certificates

A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic.

CriticalCVSS 9.4Not KEV-listedUpdated
Glexia's TakeAutomated analysiscritical

Security readout for executives and security teams

Plain-English summary

This critical Red Hat Hypershift issue lets an attacker who can reach the Konnectivity cluster endpoint connect as an agent without certificate validation. That could let them interfere with sensitive control-plane-to-node traffic. The business risk is high for hosted control plane environments because confidentiality, integrity, and some availability of cluster communications may be affected.

Executive priority

Treat as an urgent patching item for Red Hat hosted control plane environments. Prioritize systems where the Konnectivity endpoint is exposed beyond trusted cluster networks. If your organization does not use Hypershift hosted control planes or listed affected packages, urgency is lower after validation.

Technical view

The Konnectivity proxy-server agent-facing listener for hosted control planes was started without --cluster-ca-cert and without token-based agent authentication. Client certificates were not validated, enabling unauthenticated agent connections to join the routing pool and potentially proxy, inspect, modify, or drop control-plane-to-node traffic. CVSS is 9.4, CWE-306.

Likely exposure

Exposure is most likely in Red Hat hosted control plane deployments using affected multicluster-engine/hypershift-rhel9-operator packages, plus affected OADP packages listed by Red Hat. Risk depends on whether the Konnectivity cluster endpoint is reachable by an attacker.

Exploitation context

The source bundle does not show CISA KEV listing or confirmed active exploitation. Exploitation requires network reachability to the Konnectivity cluster endpoint, but no credentials or user interaction are required according to the CVSS vector.

Researcher notes

The core defect is missing authentication on the Konnectivity agent path, not a generic Kubernetes issue. Public sources provided do not include exploit code or confirmed exploitation. Fixed version details are not present in the bundle, so rely on Red Hat errata and product advisories for remediation targeting.

Mitigation direction

  • Apply the relevant Red Hat security advisories for affected products and packages.
  • Prioritize hosted control plane environments with reachable Konnectivity cluster endpoints.
  • Restrict network access to Konnectivity cluster endpoints where operationally possible.
  • Verify vendor guidance for exact fixed builds before change approval.
  • Track Hypershift PR 9031 and Red Hat Bugzilla 2502690 for implementation details.

Validation and detection

  • Inventory Red Hat MCE, Hypershift, and OADP deployments against Red Hat's affected package list.
  • Confirm Konnectivity proxy-server agent authentication is enabled after remediation.
  • Check whether agent-facing Konnectivity endpoints are reachable from untrusted networks.
  • Review Red Hat errata applicability for each cluster and operator channel.
  • Document unaffected packages separately to avoid unnecessary emergency changes.
Prepared
Confidence
medium
Sources
11

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-306: Credential and account abuse lookup

Authentication and credential weaknesses can make valid-account abuse and credential telemetry useful review starting points. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
description · low confidence lookup

Credential and access behavior lookup

The CVE wording references authentication or credential exposure, so valid-account and credential-access review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
description · low confidence lookup

Container behavior lookup

The affected technology mentions containers, so container-specific ATT&CK technique review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2026-16242 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Critical
CVSS
9.4 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
5Timeline events
1ADP providers
11Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: yesTechnical Impact: total

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
9.4CVSS 3.1CriticalCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L3.95.5redhat

Vulnerability scoring details

Base CVSS 3.1 score

9.4Critical
CVSS 3.1 vector shape for CVE-2026-16242Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. Source timelineredhat

    Made public.

  2. Source timelineredhat

    Reported to Red Hat.

  3. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  4. CVE publishedCVE Program

    The CVE record was published.

  5. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Red Hatmulticluster engine for Kubernetes 2.1multicluster-engine/hypershift-rhel9-operator, 1784905766affected
Red Hatmulticluster engine for Kubernetes 2.1multicluster-engine/hypershift-rhel9-operator, 1784905766affected
Red Hatmulticluster engine for Kubernetes 2.11multicluster-engine/hypershift-rhel9-operator, 1784945966affected
Red Hatmulticluster engine for Kubernetes 2.17multicluster-engine/hypershift-rhel9-operator, 1784856942affected
Red Hatmulticluster engine for Kubernetes 2.6multicluster-engine/hypershift-rhel9-operator, 1784905804affected
Red Hatmulticluster engine for Kubernetes 2.8multicluster-engine/hypershift-rhel9-operator, 1784905783affected
Red Hatmulticluster engine for Kubernetes 2.9multicluster-engine/hypershift-rhel9-operator, 1784905769affected
Red HatLogging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-rhel9-operatorunaffected
Red HatMulticluster Engine for Kubernetesmulticluster-engine/cluster-curator-controller-rhel9unaffected
Red HatMulticluster Engine for Kubernetesmulticluster-engine/hypershift-addon-rhel9-operatorunaffected
Red HatMulticluster Engine for Kubernetesmulticluster-engine/hypershift-cli-rhel9unaffected
Red HatMulticluster Engine for Kubernetesmulticluster-engine/managedcluster-import-controller-rhel9unaffected
Red HatOpenShift API for Data Protectionoadp/oadp-hypershift-velero-plugin-rhel9affected
Red HatOpenShift API for Data Protectionoadp/oadp-rhel9-operatoraffected
Red HatRed Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-multicluster-observability-addon-rhel9unaffected
Red HatRed Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-must-gather-rhel9unaffected
Red HatRed Hat Advanced Cluster Management for Kubernetes 2rhacm2/endpoint-monitoring-rhel9-operatorunaffected
Red HatRed Hat Advanced Cluster Management for Kubernetes 2rhacm2/grafana-dashboard-loader-rhel9unaffected
Red HatRed Hat Advanced Cluster Management for Kubernetes 2rhacm2/metrics-collector-rhel9unaffected
Red HatRed Hat Advanced Cluster Management for Kubernetes 2rhacm2/multicluster-observability-rhel9-operatorunaffected
Red HatRed Hat Advanced Cluster Management for Kubernetes 2rhacm2/rbac-query-proxy-rhel9unaffected
Red HatRed Hat OpenShift Container Platform 4openshift4/ose-aws-ebs-csi-driver-rhel9-operatorunaffected
Red HatRed Hat OpenShift Container Platform 4openshift4/ose-aws-efs-csi-driver-rhel9-operatorunaffected
Red HatRed Hat OpenShift Container Platform 4openshift4/ose-azure-disk-csi-driver-rhel9-operatorunaffected
Red HatRed Hat OpenShift Container Platform 4openshift4/ose-azure-file-csi-driver-operator-rhel9unaffected
Red HatRed Hat OpenShift Container Platform 4openshift4/ose-cluster-csi-snapshot-controller-rhel9-operatorunaffected
Red HatRed Hat OpenShift Container Platform 4openshift4/ose-cluster-network-operatorunaffected
Red HatRed Hat OpenShift Container Platform 4openshift4/ose-cluster-network-rhel9-operatorunaffected
Red HatRed Hat OpenShift Container Platform 4openshift4/ose-cluster-node-tuning-rhel9-operatorunaffected
Red HatRed Hat OpenShift Container Platform 4openshift4/ose-cluster-storage-rhel9-operatorunaffected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-306 · source CWE mapping

Missing Authentication for Critical Function

Missing Authentication for Critical Function represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.