CVE-2026-31892HIGH 8.1EPSS p18.8%

CVE-2026-31892CVE-2026-31892

Description

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 2.9.0 to before 4.0.2 and 3.7.11, A user who can submit Workflows can completely bypass all security settings defined in a WorkflowTemplate by including a podSpecPatch field in their Workflow submission. This works even when the controller is configured with templateReferencing: Strict, which is specifically documented as a mechanism to restrict users to admin-approved templates. The podSpecPatch field on a submitted Workflow takes precedence over the referenced WorkflowTemplate during spec merging and is applied directly to the pod spec at creation time with no security validation. This vulnerability is fixed in 4.0.2 and 3.7.11.

Scoring

CVSS 3.18.1 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS0.27% probability of exploitation · percentile 18.8% · 2026-06-18T12:00:27Z
Published2026-03-11
Last modified2026-03-17

Underlying weaknesses· 1

CWE-863

References

  1. https://github.com/argoproj/argo-workflows/security/advisories/GHSA-3wf5-g532-rcrr

1

TypeTargetConfidenceTier
WeaknessIncorrect Authorizationcwe-8630%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-42296
CVE
CVE-2026-42297
CVE
CVE-2025-62156
CVE
CVE-2025-32445
CVE
CVE-2026-42880
CVE
CVE-2026-49298
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.