EUVD Vulnerability Catalog
EUVD-2026-45897
Severity: CRITICAL
Base Score: 9.4
CVSS Version: 3.1
Vulnerability Description
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic.
CVSS Vector Analysis
Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
▪
Attack Vector (AV): Network
▪
Attack Complexity (AC): Low
▪
Privileges Required (PR): None
▪
User Interaction (UI): None
▪
Scope (S): Unchanged
▪
Confidentiality Impact (C): High
▪
Integrity Impact (I): High
▪
Availability Impact (A): Low
Affected Vendors & Systems
Vendor
Red Hat
References & Advisory Links
- https://access.redhat.com/errata/RHSA-2026:46885
- https://access.redhat.com/errata/RHSA-2026:47388
- https://access.redhat.com/errata/RHSA-2026:47728
- https://access.redhat.com/errata/RHSA-2026:47735
- https://access.redhat.com/errata/RHSA-2026:47949
- https://access.redhat.com/errata/RHSA-2026:47953
- https://access.redhat.com/errata/RHSA-2026:47974
- https://access.redhat.com/errata/RHSA-2026:48284
- https://access.redhat.com/errata/RHSA-2026:48657
- https://access.redhat.com/errata/RHSA-2026:48670
- https://access.redhat.com/errata/RHSA-2026:48676
- https://access.redhat.com/errata/RHSA-2026:48693
- https://access.redhat.com/errata/RHSA-2026:48699
- https://access.redhat.com/errata/RHSA-2026:50758
- https://access.redhat.com/security/cve/CVE-2026-16242
- https://bugzilla.redhat.com/show_bug.cgi?id=2502690
- https://github.com/openshift/hypershift/pull/9031
Metadata Profile
Database Authority
European Union Agency for Cybersecurity (ENISA) EUVD
Assigner
redhat
EPSS Probability
0.8
Known Aliases
GHSA-43hh-68v6-mf36
CVE-2026-16242
Published On
2026-07-20
Last Updated
2026-08-23