Container-Native Workflow Engine Vulnerability in Argo Workflows by Argo Project
CVE-2026-54526

8.9HIGH

Key Information:

Vendor

Argoproj

Vendor
CVE Published:
16 July 2026

What is CVE-2026-54526?

Argo Workflows, an open source container-native workflow engine for Kubernetes, has a vulnerability that allows users to inject arbitrary strategic merge patches into the artifact-GC pod. This issue arises from the incompleteness of the allow-list fix related to the WorkflowSpec.ArtifactGC field mapping. Affected versions prior to 3.7.15 and 4.0.6 inadequately validate user inputs for artifact garbage collection, potentially leading to exploitation through host path volumes, privilege escalation, and arbitrary command execution. Critical updates in versions 3.7.15 and 4.0.6 address this concern and should be applied immediately to ensure security.

Affected Version(s)

argo-workflows < 3.7.15 < 3.7.15

argo-workflows >= 4.0.0, < 4.0.6 < 4.0.0, 4.0.6

References

CVSS V4

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.