← Zurück zur CVE-Suche

CVE-2026-42296

Argo Workflows

Beschreibung

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, a user with create Workflow permission can bypass templateReferencing: Strict to get host network access, switch service accounts, override pod security context, add tolerations to schedule on control-plane nodes, or enable SA token mounting. This defeats the stated purpose of the feature. The practical impact depends on what Kubernetes-level controls are in place. Clusters with PodSecurity admission or OPA/Gatekeeper would independently block some of these (like hostNetwork). Clusters that rely on Argo-s Strict mode as the primary enforcement layer are fully exposed. This issue has been patched in versions 3.7.14 and 4.0.5.

CVSS 8.1EPSS 0.424%Risiko 0.84
Quelle öffnen
Veröffentlicht
2026-05-09 04:16:25
Betroffene Versionen
<3.7.14,<4.0.5
Typ
Core software
Zuletzt geändert
2026-07-24 21:10:00
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N