目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-16242— OpenShift HyperShift 授权问题漏洞

一分钟漏洞结论

影响对象
Red Hat multicluster engine for Kubernetes 2.1
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

OpenShift HyperShift是OpenShift公司的一款托管Kubernetes控制平面的云计算服务。 OpenShift HyperShift存在授权问题漏洞,该漏洞由于缺少认证导致客户端证书未被验证,远程攻击者可通过Konnectivity集群端点连接为未授权代理,加入路由池,从而可能代理、检查、修改或丢弃控制平面到节点的流量。

CVSS 9.4 · Critical EPSS 0.80% · P53

影响版本矩阵 42

厂商产品 版本范围状态
Red Hat Logging Subsystem for Red Hat OpenShift 全部 unaffected
Red Hat Multicluster Engine for Kubernetes 全部 unaffected
全部 unaffected
全部 unaffected
全部 unaffected
Red Hat multicluster engine for Kubernetes 2.1 1784905766< * unaffected
1784905766< * unaffected
Red Hat multicluster engine for Kubernetes 2.11 1784945966< * unaffected
Red Hat multicluster engine for Kubernetes 2.17 1784856942< * unaffected
Red Hat multicluster engine for Kubernetes 2.6 1784905804< * unaffected
Red Hat multicluster engine for Kubernetes 2.8 1784905783< * unaffected
Red Hat multicluster engine for Kubernetes 2.9.0 1784905769< * unaffected
Red Hat OpenShift API for Data Protection 全部 affected
全部 affected
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2 全部 unaffected
全部 unaffected
全部 unaffected
全部 unaffected
全部 unaffected
全部 unaffected
全部 unaffected
Red Hat Red Hat OpenShift Container Platform 4 全部 unaffected
全部 unaffected
全部 unaffected
全部 unaffected
全部 unaffected
全部 unaffected
全部 unaffected
全部 unaffected
… +6 条更多
Red Hat Red Hat OpenShift Container Platform 4.16 1785534428< * unaffected
Red Hat Red Hat OpenShift Container Platform 4.17 1784914869< * unaffected
Red Hat Red Hat OpenShift Container Platform 4.18 1784912882< * unaffected
Red Hat Red Hat OpenShift Container Platform 4.19 1784913720< * unaffected
Red Hat Red Hat OpenShift Container Platform 4.2 1785288843< * unaffected
Red Hat Red Hat OpenShift Container Platform 4.21 1785301941< * unaffected
Red Hat Red Hat OpenShift Container Platform 4.22 1785192936< * unaffected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-16242 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Hypershift: konnectivity proxy-server accepts agent connections without validating client certificates
来源: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy, inspect, modify, or drop control-plane-to-node traffic.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
来源: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
来源: CVE Program / CVE List V5
Vulnerability Title
OpenShift HyperShift 授权问题漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
OpenShift HyperShift是OpenShift公司的一款托管Kubernetes控制平面的云计算服务。 OpenShift HyperShift存在授权问题漏洞,该漏洞由于缺少认证导致客户端证书未被验证,远程攻击者可通过Konnectivity集群端点连接为未授权代理,加入路由池,从而可能代理、检查、修改或丢弃控制平面到节点的流量。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
Red Hat multicluster engine for Kubernetes 2.1 1784905766 ~ * cpe:/a:redhat:multicluster_engine:2.10::el9
Red Hat multicluster engine for Kubernetes 2.1 1784905766 ~ * cpe:/a:redhat:multicluster_engine:2.10::el9
Red Hat multicluster engine for Kubernetes 2.11 1784945966 ~ * cpe:/a:redhat:multicluster_engine:2.11::el9
Red Hat multicluster engine for Kubernetes 2.17 1784856942 ~ * cpe:/a:redhat:multicluster_engine:2.17::el9
Red Hat multicluster engine for Kubernetes 2.6 1784905804 ~ * cpe:/a:redhat:multicluster_engine:2.6::el9
Red Hat multicluster engine for Kubernetes 2.8 1784905783 ~ * cpe:/a:redhat:multicluster_engine:2.8::el9
Red Hat multicluster engine for Kubernetes 2.9.0 1784905769 ~ * cpe:/a:redhat:multicluster_engine:2.9::el9
Red Hat Red Hat OpenShift Container Platform 4.16 1785534428 ~ * cpe:/a:redhat:openshift:4.16::el9
Red Hat Red Hat OpenShift Container Platform 4.17 1784914869 ~ * cpe:/a:redhat:openshift:4.17::el9
Red Hat Red Hat OpenShift Container Platform 4.18 1784912882 ~ * cpe:/a:redhat:openshift:4.18::el9
Red Hat Red Hat OpenShift Container Platform 4.19 1784913720 ~ * cpe:/a:redhat:openshift:4.19::el9
Red Hat Red Hat OpenShift Container Platform 4.2 1785288843 ~ * cpe:/a:redhat:openshift:4.20::el9
Red Hat Red Hat OpenShift Container Platform 4.21 1785301941 ~ * cpe:/a:redhat:openshift:4.21::el9
Red Hat Red Hat OpenShift Container Platform 4.22 1785192936 ~ * cpe:/a:redhat:openshift:4.22::el9
Red Hat Logging Subsystem for Red Hat OpenShift - cpe:/a:redhat:logging:6
Red Hat Multicluster Engine for Kubernetes - cpe:/a:redhat:multicluster_engine
Red Hat Multicluster Engine for Kubernetes - cpe:/a:redhat:multicluster_engine
Red Hat Multicluster Engine for Kubernetes - cpe:/a:redhat:multicluster_engine
Red Hat Multicluster Engine for Kubernetes - cpe:/a:redhat:multicluster_engine
Red Hat OpenShift API for Data Protection - cpe:/a:redhat:openshift_api_data_protection:1
Red Hat OpenShift API for Data Protection - cpe:/a:redhat:openshift_api_data_protection:1
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2 - cpe:/a:redhat:acm:2
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2 - cpe:/a:redhat:acm:2
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2 - cpe:/a:redhat:acm:2
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2 - cpe:/a:redhat:acm:2
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2 - cpe:/a:redhat:acm:2
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2 - cpe:/a:redhat:acm:2
Red Hat Red Hat Advanced Cluster Management for Kubernetes 2 - cpe:/a:redhat:acm:2
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4

二、漏洞 CVE-2026-16242 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-16242 的情报信息

登录查看更多情报信息。

CVE-2026-16242 补丁与修复 (1)

CVE-2026-16242 厂商安全公告 (15)

同批安全公告 · Red Hat · 2026-07-20 · 共 8 条

CVE-2026-12701 9.0 CRITICAL Pulp Project Pulp 路径遍历漏洞
CVE-2026-64612 7.5 HIGH OpenPrinting libcupsfilters 异常处理不当漏洞
CVE-2026-12080 7.3 HIGH QEMU 后置链接漏洞
CVE-2026-15813 6.5 MEDIUM Kronosnet 缓冲区错误漏洞
CVE-2026-16277 6.5 MEDIUM Red Hat Enterprise Linux 10 缓冲区错误漏洞
CVE-2026-15588 5.3 MEDIUM GNOME GLib 资源管理错误漏洞
CVE-2026-16254 4.3 MEDIUM QUAY Claircore 缓冲区错误漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-16242

暂无评论


发表评论