All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-15416
HIGHpublished 2026-07-14 09:16 UTC · 7 days ago · modified 2026-07-15 15:16 UTC
8.9
CVSS / 10
// description
A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthenticated attacker with network access to the Argo CD repo-server to achieve remote code execution. Under certain conditions, the attacker may then manipulate cached data to deploy malicious Kubernetes resources to managed clusters, potentially resulting in complete cluster compromise.
// weaknesses (CWE)
- CWE-306
// references (6)
- https://access.redhat.com/security/cve/CVE-2026-15416
- https://bugzilla.redhat.com/show_bug.cgi?id=2496732
- https://github.com/argoproj/argo-helm/commit/0f245ab
- https://github.com/argoproj/argo-helm/security/advisories/GHSA-47m3-95c7-g2g8
- https://thehackernews.com/2026/07/unpatched-argo-cd-repo-server-flaw.html