Red Hat Security Advisory: multicluster engine for Kubernetes v2.9.6 security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2026-16242 — hypershift: Konnectivity proxy-server accepts agent connections without validating client certificates CVE-2026-17107 — cluster-proxy: cluster-proxy: Impersonation header injection in service-proxy grants cluster-admin on every managed cluster
🎯 Affected products121
- multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:51660739042f40f3b605e3ec8cabca079531e594840c58ef1e68488f02daae50_s390x as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:b72c300f7779a0d52c853467709fed3405978f80b97071b719a720bf5253aac7_arm64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:c773b1ff7d46ae93af5f0107e9aaa5553ad8c2969cf5fae697606e8ba4413161_ppc64le as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/addon-manager-rhel9@sha256:f2b1ea89001a5589317bfa45e0e16456e27c503687db0ad0e9ec0a1502d9a6d9_amd64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:1f7829a7db6cf88c47109bb88a988e9426a460b818b412b367cb5466c3fa1a61_s390x as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:91055456a028ea9d430df72ca382e3a90a76f74d54cfb1b1190798fa376300f2_amd64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:a715dc56d04a6f09b35519641c209c84b1c926d24cd43d54716e7321254571be_ppc64le as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:b15498c550e2597ee7ecb4e0a38189cf9fed807bdeb6d67b2eaff493c7e81f3b_arm64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:7f0e7edd9845622efea8df92350e8e25581617e05d21b0bac36bd245313efc0f_arm64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:a5247449bfb03f65147ec30d6694851925038820c9f65fb2d121df4e19f138af_s390x as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:d3d5115fed1566371c4d6e50e50d5005a63a28043bcfef53c91f24d92d33055b_amd64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/capoa-bootstrap-rhel9@sha256:d935bd9d2f36a439d2e43b294cb396d4001edb6a0f170cfe82f38bbbaf0a3975_ppc64le as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:4656e3e93871b15b2698fbc8819515a21266ce3017a9ece31de9dca6837531ee_arm64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:466ac487359a228df40d187581ae3733f4417a8720ca3e91a0ee17853ccfc873_ppc64le as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:6aa784d6b5c6084dcfb5d83b45ade4ab58b4969b0b13115eb4d6a4e494264928_amd64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/capoa-control-plane-rhel9@sha256:e437b4dccab913b24a015081d7a4a8a94d03a407e58dce97f518f56fd003f92b_s390x as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:2b87874e7e95b2c87becc1f89e6a969927cf7077d9c738f8a3da5b422a81bf8b_ppc64le as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:6349ccc222f92889166e53cb6af9b68db171baaf6eb974463d427de04a2a0be3_arm64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:c88bb08c4f3c381cbc566b04b46c13f1e9e4eb9be75b30372aee5cf65c6e7549_s390x as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-api-provider-agent-rhel9@sha256:d54e902a7fd472bed227bcae35b4fd378f9185641e0f384cfb885816d10b7232_amd64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:b3aa6e6c02cbe81844676fdf04cd7080cd62685c5d5eb7ae17062d1748af6c02_amd64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:c7177391f7275d140c5a2da3793e52f9f06548da004759b27aa667803d6959eb_ppc64le as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:e8ecef5ef2d76e3d469636ba2cbf65371c82813150270bc088425c4fb5ce6fae_arm64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-api-provider-kubevirt-rhel9@sha256:f662b1155fda28d3fd3081d0ef49ec707a538e208953460dd14097bb79455ea5_s390x as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:02c6dcbf817d479fba695e59e5f0588c7fce19c723f7a1e079a9dbaa530d52cb_ppc64le as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:5dc9e286e42d08e6c9c59b699350fc6f3d0c58e94ddb9b9bfbff2ae9bf43413a_arm64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:93eab8f6d49a40667beaf65958382137aa6348b5e6d38d1f575b09dfde2c6648_s390x as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-curator-controller-rhel9@sha256:b617dc467de8d93539627f7921c72742040fd13c386dcb0b36a496e8f03685dc_amd64 as a component of multicluster engine for Kubernetes 2.9
- registry.redhat.io/multicluster-engine/cluster-image-set-controller-rhel9@sha256:55d63b0f405b102e7c54ddc48963c4cff45088580bf61aaf42ff955646fa67be_arm64 as a component of multicluster engine for Kubernetes 2.9
- +91 more not shown
✅ Remediation
For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.14/html/clusters/cluster_mce_overview#mce-install-intro Workaround: Until an update that configures Konnectivity agent authentication is applied, restrict network access to the Konnectivity cluster (agent) endpoint so that only trusted worker networks can reach it. For NodePort or LoadBalancer publishing, limit ingress to port 8091 to worker node subnet ranges. For Route-based publishing, restrict access to the Konnectivity route to trusted networks where possible. These controls reduce the chance that an unauthenticated attacker can reach the agent listener; they do not replace proper agent client-certificate (or token) authentication. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:47953
- externalhttps://access.redhat.com/security/cve/CVE-2026-16242
- externalhttps://access.redhat.com/security/cve/CVE-2026-17107
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_47953.json