THREAT OPS › Threat News › [NVD] CVE-2026-16242 (CRITICAL 9.4) — A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach th
[NVD] CVE-2026-16242 (CRITICAL 9.4) — A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach th
CVE-2026-16242 CVSS: 9.4 CRITICAL Published: 2026-07-20T08:16:29.833
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as a
Indicators of compromise
- CVE-2026-16242cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-16242