EN
en direct
Élevée CVSS 8.9

CVE-2026-54526

Analyse NVD en cours

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 3.7.15 and 4.0.6, the allow-list fix for CVE-2026-31892 is incomplete because workflow/util/merge.go ValidateUserOverrides and SanitizeUserWorkflowSpec walk only the top-level fields of WorkflowSpec via reflection, and WorkflowSpec.ArtifactGC is allow-listed wholesale; the struct behind that field, WorkflowLevelArtifactGC, has a PodSpecPatch sub-field whose contents flow unmodified into util.ApplyPodSpecPatch on the artifact-GC pod, the same sink the original fix closed for WorkflowSpec.PodSpecPatch, so a user submitting a Workflow under templateReferencing: Strict or Secure (against a referenced WorkflowTemplate that declares an output artifact and setting spec.artifactGC.strategy: OnWorkflowCompletion) can still inject an arbitrary strategic merge patch into the artifact-GC pod, including hostPath volumes, privileged: true, arbitrary image and command, and hostNetwork: true, defeating the stated purpose of Strict/Secure reference mode. This issue is fixed in versions 3.7.15 and 4.0.6.

Ce que ça veut dire

Exposition
Exploitable à distance depuis le réseau, avec un compte utilisateur ordinaire et sans action de la victime. Elle dépend en outre de circonstances que l’attaquant ne maîtrise pas.
Impact
Un attaquant peut lire des données sensibles et modifier ou détruire des données. L’atteinte déborde du composant vulnérable vers d’autres parties du système.
Faiblesse
Le contrôle d’accès est mal appliqué : une ressource protégée reste atteignable sans les droits requis.
Probabilité
Le score EPSS reste bas : rien n’annonce une exploitation imminente, ce qui ne dispense pas de corriger.

À faireÀ intégrer au prochain cycle de correctifs.

Lecture automatique du vecteur CVSS, du type de faiblesse (CWE) et du score EPSS. La description technique ci-dessus reste celle publiée par le NIST, en anglais.

Publié
16 juillet 2026
CVSS
8.9 (v4.0) CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS
0,25 % probabilité d'exploitation sous 30 jours · au-dessus de 16 % des CVE
Faiblesse
CWE-284
Sources
nvd
Références

Tapez au moins deux caractères.

naviguer ouvrir esc fermer