PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-28229 Argoproj CVE debrief

CVE-2026-28229 is a critical vulnerability in Argo Workflows, an open-source container-native workflow engine for Kubernetes. The vulnerability allows any client to retrieve WorkflowTemplates and ClusterWorkflowTemplates without proper authorization, potentially leaking sensitive template content, including embedded Secret manifests. This issue was fixed in versions 4.0.2 and 3.7.11. The vulnerability has a CVSS score of 9.8 and is considered CRITICAL.

Vendor
Argoproj
Product
Argo Workflows
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-11
Original CVE updated
2026-07-15
Advisory published
2026-03-11
Advisory updated
2026-07-15

Who should care

Organizations using Argo Workflows, especially those with sensitive data in workflow templates, should prioritize patching to prevent unauthorized access. Kubernetes administrators and security teams should assess their exposure and take necessary actions. Developers using Argo Workflows in their applications should also be aware of this vulnerability.

Technical summary

The vulnerability exists in the Workflow templates endpoints of Argo Workflows. Prior to versions 4.0.2 and 3.7.11, any client can retrieve WorkflowTemplates and ClusterWorkflowTemplates without proper authorization. This can lead to the exposure of sensitive template content, including embedded Secret manifests. The issue arises from the lack of proper authorization checks in the affected endpoints.

Defensive priority

High priority should be given to patching Argo Workflows installations to prevent exploitation. Immediate action is recommended for environments with sensitive data in workflow templates.

Recommended defensive actions

  • Patch Argo Workflows to version 4.0.2 or 3.7.11
  • Review and update workflow templates to ensure sensitive data is properly secured
  • Implement additional authorization checks for workflow template access
  • Monitor for suspicious activity related to workflow template retrieval
  • Consider compensating controls, such as limiting access to workflow templates

Evidence notes

The vulnerability was reported and fixed by the Argo Workflows maintainers. The CVE was published on March 11, 2026, and last modified on June 30, 2026. Multiple sources, including NVD and Red Hat, have documented this vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-28229 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-28229

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-28229 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-28229

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://github.com/argoproj/argo-workflows/security/advisories/GHSA-56px-hm34-xqj5

    [email protected] - Exploit, Vendor Advisory

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:10184

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/security/cve/CVE-2026-28229

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28229.json

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.