CVE-2026-54526: CWE-284: Improper Access Control in argoproj argo-workflows
CVE-2026-54526 is a high-severity improper access control vulnerability in argoproj argo-workflows. It arises because the allow-list fix for a previous vulnerability is incomplete, allowing users to inject arbitrary strategic merge patches into the artifact garbage collection pod specification. This can lead to privilege escalation by enabling configurations such as privileged containers, host network access, and arbitrary commands. The vulnerability affects versions prior to 3.7.15 and 4.0.6. A patch is available to address this issue.
AI Analysis
Technical Summary
The vulnerability stems from incomplete validation in the allow-list for user overrides in argo-workflows. Specifically, the WorkflowSpec.ArtifactGC field is allow-listed wholesale, including its PodSpecPatch sub-field, which is passed unmodified to a strategic merge patch function applied to the artifact garbage collection pod. This allows a user submitting a Workflow under strict or secure template referencing modes to inject arbitrary pod specification patches, including privileged settings and host network access, circumventing intended security restrictions. The flaw exists because the validation only inspects top-level fields and does not recursively validate sub-fields like PodSpecPatch within ArtifactGC. The vulnerability requires the referenced WorkflowTemplate to have at least one template with an output artifact and the user to specify an artifactGC strategy that triggers the patch application. The affected versions are all releases before 3.7.15 and 4.0.6. The CVSS 4.0 score is 8.9, reflecting high impact with network attack vector, low attack complexity, and partial privileges required.
Potential Impact
Exploitation allows a user with limited privileges to escalate access by injecting arbitrary pod specification patches into the artifact garbage collection pod. This can enable privileged container execution, host network access, arbitrary images and commands, and override hardened security contexts. The vulnerability defeats the security intent of strict or secure template referencing modes, potentially compromising cluster security and workload isolation.
Mitigation Recommendations
A patch is available for this vulnerability. Users should upgrade argo-workflows to version 3.7.15 or later, or 4.0.6 or later, where this issue is fixed. Until patched, avoid using allow-listed ArtifactGC.PodSpecPatch fields or restrict workflow submissions to trusted users. There is no indication from the vendor advisory that any other mitigations or workarounds are sufficient.
CVE-2026-54526: CWE-284: Improper Access Control in argoproj argo-workflows
Description
CVE-2026-54526 is a high-severity improper access control vulnerability in argoproj argo-workflows. It arises because the allow-list fix for a previous vulnerability is incomplete, allowing users to inject arbitrary strategic merge patches into the artifact garbage collection pod specification. This can lead to privilege escalation by enabling configurations such as privileged containers, host network access, and arbitrary commands. The vulnerability affects versions prior to 3.7.15 and 4.0.6. A patch is available to address this issue.
CVSS v4.0
Score 8.9high
Affected software
pkg:github/argoproj/argo-workflowsRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability stems from incomplete validation in the allow-list for user overrides in argo-workflows. Specifically, the WorkflowSpec.ArtifactGC field is allow-listed wholesale, including its PodSpecPatch sub-field, which is passed unmodified to a strategic merge patch function applied to the artifact garbage collection pod. This allows a user submitting a Workflow under strict or secure template referencing modes to inject arbitrary pod specification patches, including privileged settings and host network access, circumventing intended security restrictions. The flaw exists because the validation only inspects top-level fields and does not recursively validate sub-fields like PodSpecPatch within ArtifactGC. The vulnerability requires the referenced WorkflowTemplate to have at least one template with an output artifact and the user to specify an artifactGC strategy that triggers the patch application. The affected versions are all releases before 3.7.15 and 4.0.6. The CVSS 4.0 score is 8.9, reflecting high impact with network attack vector, low attack complexity, and partial privileges required.
Potential Impact
Exploitation allows a user with limited privileges to escalate access by injecting arbitrary pod specification patches into the artifact garbage collection pod. This can enable privileged container execution, host network access, arbitrary images and commands, and override hardened security contexts. The vulnerability defeats the security intent of strict or secure template referencing modes, potentially compromising cluster security and workload isolation.
Mitigation Recommendations
A patch is available for this vulnerability. Users should upgrade argo-workflows to version 3.7.15 or later, or 4.0.6 or later, where this issue is fixed. Until patched, avoid using allow-listed ArtifactGC.PodSpecPatch fields or restrict workflow submissions to trusted users. There is no indication from the vendor advisory that any other mitigations or workarounds are sufficient.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-15T18:40:01.651Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a592e8468715ace4390ca34
Added to database: 07/16/2026, 19:18:28 UTC
Last enriched: 08/13/2026, 18:11:23 UTC
Last updated: 08/29/2026, 22:52:12 UTC
Views: 108
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.