HIGH🇵🇱 Wersja polska

CVE-2026-31892

CVSS 8.9v4.0pub. 2026-03-11upd. 2026-06-30

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 2.9.0 to before 4.0.2 and 3.7.11, A user who can submit Workflows can completely bypass all security settings defined in a WorkflowTemplate by including a podSpecPatch field in their Workflow submission. This works even when the controller is configured with templateReferencing: Strict, which is specifically documented as a mechanism to restrict users to admin-approved templates. The podSpecPatch field on a submitted Workflow takes precedence over the referenced WorkflowTemplate during spec merging and is applied directly to the pod spec at creation time with no security validation. This vulnerability is fixed in 4.0.2 and 3.7.11.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Argoproj Argo Workflows

    APP
    Argoproj
    2.9.0 – 3.7.11 (excl.)4.0.0 – 4.0.2 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Container
CWE
References

Related vulnerabilities

CVE-2026-28229CRITICAL9.8PL ✓same product

Argo Workflows: nieautoryzowany dostęp do szablonów workflow i wykradanie sekretów

CVE-2026-54526HIGH8.9PL ✓same product

Argo Workflows: niepełna naprawa CVE-2026-31892 — inject patch do poda artifact-GC

CVE-2026-42296HIGH8.1same product

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernete...

CVE-2026-42294HIGH8.2same product

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernete...

CVE-2026-42295HIGH8.5same product

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernete...