CVE-2026-31892Disclosure(argoproj / argo_workflows)

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 2.9.0 to before 4.0.2 and 3.7.11, A user who can submit Workflows can completely bypass all security settings defined in a WorkflowTemplate by including a podSpecPatch field in their Workflow submission. This works even when the controller is configured with templateReferencing: Strict, which is specifically documented as a mechanism to restrict users to admin-approved templates. The podSpecPatch field on a submitted Workflow takes precedence over the referenced WorkflowTemplate during spec merging and is applied directly to the pod spec at creation time with no security validation. This vulnerability is fixed in 4.0.2 and 3.7.11.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863CWE-807

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • argo_workflows

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-12); latest day: 2
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
argo_workflows

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-03-11: 1Mentions · 2026-03-12: 2Mentions · 2026-03-15: 2Technical Details · 2026-03-11: 1Technical Details · 2026-03-12: 103-1103-1203-15
Signal classification2 categories
Disclosure
360.0%
General
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-111
Disclosure1
2026-03-122
Disclosure2
2026-03-152
General2
Full discourse5 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-31892 Security Bypass in Argo Workflows via Unauthorized podSpecPatch Field Manipulation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-31892

    Post summary

    The text merely announces a new CVE affecting Argo Workflows, noting a bypass via unauthorized podSpecPatch manipulation, but provides no further technical, exploit, or mitigation details.

    0001017
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-31892 Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 2.9.0 to before 4.0.2 and 3.7.11, A user who can… https://www.cve.org/CVERecord?id=CVE-2026-31892 ----- Traducción: CVE-2026-31892 Arg… http://infoflow.cloud`

    Post summary

    The snippet merely references CVE-2026-31892 for Argo Workflows, linking to the CVE record, without providing any exploitation details, patches, or technical specifics.

    0000035
    57 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-31892 Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 2.9.0 to before 4.0.2 and 3.7.11, A user who can… https://www.cve.org/CVERecord?id=CVE-2026-31892

    Post summary

    The post merely lists the CVE identifier, affected Argo Workflows versions, and a link to the CVE record, without further technical, exploit, or mitigation details.

    00000198
    56.7K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 https://dailycve.com/argo-workflows-security-bypass-#cve-2026-31892-critical/ Adobe Substance 3D Painter, Out-of-Bounds Read, CVE-2026-27216 (Medium)

    Post summary

    The post links to a DailyCVE article about CVE-2026-31892 security bypass in Argo Workflows and mentions CVE-2026-27216 as an out‑of‑bounds read vulnerability in Adobe Substance 3D Painter with Medium severity.

    0000060
    167 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 https://dailycve.com/quill-unbounded-read-#cve-2026-31960-medium/ Argo Workflows, Security Bypass, CVE-2026-31892 (Critical)

    Post summary

    The text provides a link to CVE information for two vulnerabilities but contains no proof of concept, exploit details, patches, or evidence of active exploitation.

    0000032
    167 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appargoprojargo_workflows-go-

Explore more