CVE-2026-42296
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, a user with create Workflow permission can bypass templateReferencing: Strict to get host network access, switch service accounts, override pod security context, add tolerations to schedule on control-plane nodes, or enable SA token mounting. This defeats the stated purpose of the feature. The practical impact depends on what Kubernetes-level controls are in place.
Leer descripción completaMostrar menos
Clusters with PodSecurity admission or OPA/Gatekeeper would independently block some of these (like hostNetwork). Clusters that rely on Argo's Strict mode as the primary enforcement layer are fully exposed. This issue has been patched in versions 3.7.14 and 4.0.5.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Puntuación base: 8.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.49%
- Percentil entre todas las CVEs puntuadas: 40
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1210Exploitation of Remote Serviceslateral movement75 % - Impacto principal
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto secundario
T1078.001Default Accountsstealth · persistence · privilege escalation · initial access80 % - Impacto secundario
T1574.012COR_PROFILERstealth · execution70 %
Acceso remoto con PR:L permite usuario autenticado escalar privilegios (hostNetwork, SA override, pod security context) en Kubernetes; bypassa controles de aplicación.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-863
- CWE-863
Referencias
- https://github.com/argoproj/argo-workflows/commit/534f4ff1cbd86908e8ff76d97d553ad5a49a950d
- https://github.com/argoproj/argo-workflows/releases/tag/v3.7.14
- https://github.com/argoproj/argo-workflows/releases/tag/v4.0.5
- https://github.com/argoproj/argo-workflows/security/advisories/GHSA-3775-99mw-8rp4
- https://access.redhat.com/security/cve/CVE-2026-42296
- https://bugzilla.redhat.com/show_bug.cgi?id=2468446
- https://github.com/argoproj/argo-workflows/security/advisories/GHSA-3775-99mw-8rp4
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42296.json
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-42296",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-42296",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-05-12T17:51:11.816105Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 2.8
},
{
"type": "Secondary",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "argoproj",
"product": "argo-workflows",
"versions": [
{
"status": "affected",
"version": "< 3.7.14"
},
{
"status": "affected",
"version": ">= 4.0.0, < 4.0.5"
}
]
}
]
},
{
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"affectedData": [
{
"cpes": [
"cpe:/a:redhat:openshift_ai"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI (RHOAI)",
"packageName": "rhoai/odh-data-science-pipelines-argo-argoexec-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI (RHOAI)",
"packageName": "rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI (RHOAI)",
"packageName": "rhoai/odh-ml-pipelines-api-server-v2-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI (RHOAI)",
"packageName": "rhoai/odh-ml-pipelines-driver-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI (RHOAI)",
"packageName": "rhoai/odh-ml-pipelines-launcher-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI (RHOAI)",
"packageName": "rhoai/odh-ml-pipelines-persistenceagent-v2-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_ai"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift AI (RHOAI)",
"packageName": "rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
}
]
}
],
"published": "2026-05-09T04:16:25.563",
"references": [
{
"url": "https://github.com/argoproj/argo-workflows/commit/534f4ff1cbd86908e8ff76d97d553ad5a49a950d",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/argoproj/argo-workflows/releases/tag/v3.7.14",
"tags": [
"Release Notes"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/argoproj/argo-workflows/releases/tag/v4.0.5",
"tags": [
"Release Notes"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/argoproj/argo-workflows/security/advisories/GHSA-3775-99mw-8rp4",
"tags": [
"Exploit",
"Mitigation",
"Vendor Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2026-42296",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2468446",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://github.com/argoproj/argo-workflows/security/advisories/GHSA-3775-99mw-8rp4",
"tags": [
"Exploit",
"Mitigation",
"Vendor Advisory"
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
},
{
"url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42296.json",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-863"
}
]
},
{
"type": "Secondary",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"description": [
{
"lang": "en",
"value": "CWE-863"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, a user with create Workflow permission can bypass templateReferencing: Strict to get host network access, switch service accounts, override pod security context, add tolerations to schedule on control-plane nodes, or enable SA token mounting. This defeats the stated purpose of the feature. The practical impact depends on what Kubernetes-level controls are in place. Clusters with PodSecurity admission or OPA/Gatekeeper would independently block some of these (like hostNetwork). Clusters that rely on Argo's Strict mode as the primary enforcement layer are fully exposed. This issue has been patched in versions 3.7.14 and 4.0.5."
},
{
"lang": "es",
"value": "Argo Workflows es un motor de flujo de trabajo de código abierto nativo de contenedores para orquestar trabajos paralelos en Kubernetes. Antes de las versiones 3.7.14 y 4.0.5, un usuario con permiso para crear flujos de trabajo (Workflow) puede eludir templateReferencing: Strict para obtener acceso a la red del host, cambiar cuentas de servicio, anular el contexto de seguridad del pod, añadir tolerancias para programar en nodos del plano de control, o habilitar el montaje de tokens de SA. Esto anula el propósito declarado de la característica. El impacto práctico depende de los controles a nivel de Kubernetes que estén implementados. Los clústeres con admisión de PodSecurity o OPA/Gatekeeper bloquearían independientemente algunos de estos (como hostNetwork). Los clústeres que dependen del modo Strict de Argo como capa de aplicación principal están completamente expuestos. Este problema ha sido parcheado en las versiones 3.7.14 y 4.0.5."
}
],
"lastModified": "2026-07-24T21:10:00.143",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:argoproj:argo_workflows:*:*:*:*:*:go:*:*",
"vulnerable": true,
"matchCriteriaId": "A2883DF4-7751-4133-BB8B-02F2DF7D50D1",
"versionEndExcluding": "3.7.14"
},
{
"criteria": "cpe:2.3:a:argoproj:argo_workflows:*:*:*:*:*:go:*:*",
"vulnerable": true,
"matchCriteriaId": "675D5F2B-A490-42EB-B1A1-0CE05D2BB4CF",
"versionEndExcluding": "4.0.5",
"versionStartIncluding": "4.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}