{"id":"CVE-2026-31892","title":"github.com/argoproj/argo-workflows: Argo Workflows: Security bypass allows privilege escalation via podSpecPatch field (CVE-2026-31892)","summary":"A flaw was found in Argo Workflows. A user with privileges to submit workflows can bypass security settings defined in a WorkflowTemplate by including a `podSpecPatch` field in their workflow submission. This allows them to circumvent rest…","severity":"high","cvss":8.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N","cvssSource":"vendor","cwe":"CWE-807","vendor":"Red Hat","product":"Red Hat OpenShift AI 2.25","affected":["openshift_ai 2.25"],"patched":["openshift_ai 2.25"],"published":"2026-03-11","updated":"2026-09-23","sourceUpdated":"2026-09-23T18:23:43+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31892.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-31892.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-31892"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2446551"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-31892"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-31892"},{"url":"https://github.com/argoproj/argo-workflows/security/advisories/GHSA-3wf5-g532-rcrr"},{"url":"https://access.redhat.com/errata/RHSA-2026:10184"},{"url":"https://github.com/argoproj/argo-workflows"}],"tags":["csaf","vex","red-hat","osv","go"],"epss":0.00488,"epssPercentile":0.41127,"aliases":["GHSA-3wf5-g532-rcrr","BIT-argo-workflows-2026-31892","GO-2026-4681"],"ecosystem":"go","ingestedAt":"2026-09-12T03:13:01.750Z","slug":"CVE-2026-31892","body":"## Overview\n\nA flaw was found in Argo Workflows. A user with privileges to submit workflows can bypass security settings defined in a WorkflowTemplate by including a `podSpecPatch` field in their workflow submission. This allows them to circumvent restrictions, even when `templateReferencing: Strict` is configured, potentially leading to unauthorized resource access or privilege escalation.\n\n## Vendor advisories\n\n- **RHSA-2026:10184** · Red Hat · fixed in: Red Hat OpenShift AI 2.25 · released 2026-04-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:10184)\n\n**github.com/argoproj/argo-workflows: Argo Workflows: Security bypass allows privilege escalation via podSpecPatch field** — rated Important by Red Hat. Released 2026-03-11, updated 2026-09-23.\n\nFixed:\n\n- Red Hat OpenShift AI 2.25\n\nNot affected:\n\n- Red Hat OpenShift AI 2.25\n- Red Hat OpenShift AI (RHOAI)\n\n## Remediation\n\nFor Red Hat OpenShift AI 2.25.5 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this errata update:\n\nhttps://docs.redhat.com/en/documentation/red_hat_openshift_ai/ https://access.redhat.com/errata/RHSA-2026:10184\n\n## Package advisory (CVE-2026-31892)\n\nAffected packages:\n\n- `github.com/argoproj/argo-workflows/v4 < 4.0.2`\n- `github.com/argoproj/argo-workflows/v3 < 3.7.11`\n- `github.com/argoproj/argo-workflows >= 2.9.0`\n\nPatched in:\n\n- `github.com/argoproj/argo-workflows/v4 4.0.2`\n- `github.com/argoproj/argo-workflows/v3 3.7.11`\n\nSource: https://osv.dev/vulnerability/GHSA-3wf5-g532-rcrr","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":46.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":209992,"id":"CVE-2026-31892","ts":1790235644368,"field":"cvss","old":null,"new":"8.5"}]}