logo

Konnectivity Vulnerability Lets Unauthenticated Attackers Intercept Control-Plane Traffic

ID: fc788a4c-d518-5859-bbb0-72778a953cd1

STIX ID: report--fc788a4c-d518-5859-bbb0-72778a953cd1

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-07-24

Date Updated: 2026-07-25

Author: Do Son

...
...

**CVE-2026-16242 — Konnectivity proxy-server authentication bypass (CVSS 9.4):** A misconfiguration in the Konnectivity proxy-server for hosted OpenShift control planes allows the agent listener to start without validating client certificates or token-based authentication, enabling an unauthenticated remote agent to join the routing pool and proxy, inspect, modify, or drop control-plane-to-node traffic; vendor patching and network access restrictions are recommended until a fix is available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.