THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-16242 (CRITICAL 9.4) — A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach th

[NVD] CVE-2026-16242 (CRITICAL 9.4) — A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach th

mednvdPublished 2026-07-20

CVE-2026-16242 CVSS: 9.4 CRITICAL Published: 2026-07-20T08:16:29.833

A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as a

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-16242