PT-2026-61539 · Unknown · Konnectivity Proxy-Server

CVE-2026-16242

·

Published

2026-07-20

·

Updated

2026-07-20

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Konnectivity proxy-server (affected versions not specified)
Description A flaw in the configuration of the proxy-server for hosted control planes allows the agent-facing listener to start without the --cluster-ca-cert flag and without token-based agent authentication. Consequently, client certificates are not validated, enabling a remote attacker with access to the Konnectivity cluster endpoint to connect as an unauthenticated agent. This allows the attacker to join the routing pool and potentially proxy, inspect, modify, or drop traffic between the control plane and the nodes.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16242

Affected Products

Konnectivity Proxy-Server