CVE-2026-31892 identifies a critical security bypass vulnerability affecting Argo Workflows versions 2.9.0 to before 4.0.2 and 3.7.11. An authenticated user with workflow submission privileges can completely bypass all security settings defined in a WorkflowTemplate by including a `podSpecPatch` field, even when strict template referencing is enabled. Rated with a CVSS score of 8.1 (High), this flaw has a network attack vector and low attack complexity, enabling high confidentiality and integrity impacts. There is currently no evidence of active exploitation, public exploit code, or significant community discussion beyond a single vendor security update.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.9.0, < 3.7.11CPE matchmatch criteria | cpe:2.3:a:argoproj:argo_workflows:*:*:*:*:*:go:*:* | ||
>= 4.0.0, < 4.0.2CPE matchmatch criteria | cpe:2.3:a:argoproj:argo_workflows:*:*:*:*:*:go:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.