CVE-2026-16242

Red Hat · Logging Subsystem for Red Hat OpenShift

A flaw in the Konnectivity proxy-server configuration for hosted control planes allows unauthenticated remote attackers to connect as an agent and manipulate control-plane-to-node traffic.

Executive summary

A critical authentication bypass in the Red Hat Logging Subsystem for OpenShift allows unauthenticated remote attackers to intercept or modify internal cluster traffic.

Vulnerability

This vulnerability involves a missing authentication check (CWE-306) within the Konnectivity proxy-server agent-facing listener. Because the listener fails to validate client certificates or require tokens, remote attackers can join the routing pool as unauthenticated agents.

Business impact

The CVSS score of 9.4 classifies this as a critical risk, as it allows full network-level control over communication between the control plane and nodes. Successful exploitation could lead to unauthorized data inspection, modification of sensitive control traffic, or a complete compromise of the cluster integrity, resulting in significant operational downtime and potential data exfiltration.

Remediation

Immediate Action: Review Red Hat security bulletins and apply all available updates for the Logging Subsystem and associated Multicluster Engine components.

Proactive Monitoring: Monitor network traffic and access logs for unauthorized connections to the Konnectivity cluster endpoint, specifically looking for unexpected agent joining events.

Compensating Controls: Implement strict network segmentation and firewall rules to restrict access to the Konnectivity proxy-server endpoint to known, trusted infrastructure components only.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical nature of this flaw, security teams must prioritize patching affected OpenShift environments. If an immediate patch is not available, restricting network access to the affected endpoint is essential to mitigate the risk of unauthorized cluster manipulation.