PatchSiren cyber security CVE debrief
CVE-2026-31892 Argoproj CVE debrief
CVE-2026-31892 is a high-severity vulnerability in Argo Workflows, an open-source container-native workflow engine for Kubernetes. The vulnerability allows a user who can submit Workflows to completely bypass all security settings defined in a WorkflowTemplate by including a podSpecPatch field in their Workflow submission. This bypass occurs even when the controller is configured with templateReferencing: Strict, which is intended to restrict users to admin-approved templates. The podSpecPatch field takes precedence over the referenced WorkflowTemplate during spec merging and is applied directly to the pod spec at creation time without security validation. The vulnerability is fixed in versions 4.0.2 and 3.7.11.
- Vendor
- Argoproj
- Product
- Argo Workflows
- CVSS
- HIGH 8.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-11
- Original CVE updated
- 2026-07-15
- Advisory published
- 2026-03-11
- Advisory updated
- 2026-07-15
Who should care
Users of Argo Workflows, especially those who allow untrusted users to submit Workflows, should be aware of this vulnerability. Security teams and administrators responsible for Kubernetes environments where Argo Workflows is deployed should prioritize patching to prevent potential security breaches.
Technical summary
The vulnerability in Argo Workflows arises from the podSpecPatch field in Workflow submissions, which can override security settings in WorkflowTemplates. Even with strict template referencing enabled, users can bypass security by including this field. The issue is addressed in Argo Workflows versions 4.0.2 and 3.7.11. Affected versions include 2.9.0 to before 4.0.2 and 3.7.11. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 8.9, indicating a high severity.
Defensive priority
Given the high CVSS score of 8.9, defenders should prioritize patching Argo Workflows instances to versions 4.0.2 or 3.7.11. Immediate action is recommended for environments where untrusted users can submit Workflows.
Recommended defensive actions
- Patch Argo Workflows to version 4.0.2 or 3.7.11.
- Restrict Workflow submissions to trusted users.
- Monitor for suspicious Workflow submissions.
- Review and update WorkflowTemplates to ensure security settings are properly enforced.
- Consider implementing additional security controls, such as network policies or pod security policies, to mitigate potential impacts.
Evidence notes
The CVE-2026-31892 vulnerability is documented in the official CVE record and the National Vulnerability Database (NVD). Multiple sources, including GitHub security advisories and Red Hat security bulletins, provide additional details and mitigation strategies.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-31892 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-31892
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-31892 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-31892
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/argoproj/argo-workflows/security/advisories/GHSA-3wf5-g532-rcrr
[email protected] - Exploit, Mitigation, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:10184
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-31892
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31892.json
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.