Описание
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, a user with create Workflow permission can bypass templateReferencing: Strict to get host network access, switch service accounts, override pod security context, add tolerations to schedule on control-plane nodes, or enable SA token mounting. This defeats the stated purpose of the feature. The practical impact depends on what Kubernetes-level controls are in place. Clusters with PodSecurity admission or OPA/Gatekeeper would independently block some of these (like hostNetwork). Clusters that rely on Argo's Strict mode as the primary enforcement layer are fully exposed. This issue has been patched in versions 3.7.14 and 4.0.5.
A flaw was found in Argo Workflows. A user with create Workflow permission can bypass the templateReferencing: Strict security control. This bypass allows the user to gain host network access, switch service accounts, override pod security context, add tolerations to schedule on control-plane nodes, or enable Service Account (SA) token mounting. This could lead to privilege escalation and unauthorized access within the Kubernetes cluster.
Отчет
Severity: Important This issue is classified as Important because a user with create Workflow permission can bypass Argo Workflows templateReferencing Strict or Secure controls and influence pod security posture (hostNetwork, serviceAccountName, securityContext, tolerations, automountServiceAccountToken) when submitting workflows that reference WorkflowTemplates. RH CVSS 8.1 reflects network reachability, low-privilege attacker (workflow submitter), and high confidentiality/integrity impact in the cluster context (PR:L, UI:N). Red Hat OpenShift AI ships Argo Workflows as part of Data Science Pipelines (workflow-controller and argoexec containers, plus related ml-pipelines components) on supported streams rhoai-2.25, rhoai-3.3, and rhoai-3.4. Bundled versions are below the upstream fix (3.7.14). Practical exploitability also depends on Kubernetes-level controls (PodSecurity admission, OPA/Gatekeeper) and namespace RBAC for workflow creation. This CVE is an incomplete fix for CVE-2026-31892; clusters that received the earlier 3.7.11-class update remain affected until upgraded to 3.7.14 or later on the 3.x line.
Меры по смягчению последствий
Upgrade Argo Workflows to version 3.7.14 or later (3.x line) or 4.0.5+ (4.x line) in affected Red Hat OpenShift AI releases. Red Hat OpenShift AI engineering is expected to deliver updated Data Science Pipelines builds for affected streams (rhoai-2.25, rhoai-3.3, rhoai-3.4). As a defense-in-depth measure, enforce PodSecurity admission or policy controls to block hostNetwork, privileged pods, and unauthorized service account use independently of Argo templateReferencing settings. Restrict Workflow create permissions to trusted principals.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-data-science-pipelines-argo-argoexec-rhel9 | Affected | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9 | Affected | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-ml-pipelines-api-server-v2-rhel9 | Affected | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-ml-pipelines-driver-rhel9 | Affected | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-ml-pipelines-launcher-rhel9 | Affected | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-ml-pipelines-persistenceagent-v2-rhel9 | Affected | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel9 | Affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
8.1 High
CVSS3
Связанные уязвимости
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, a user with create Workflow permission can bypass templateReferencing: Strict to get host network access, switch service accounts, override pod security context, add tolerations to schedule on control-plane nodes, or enable SA token mounting. This defeats the stated purpose of the feature. The practical impact depends on what Kubernetes-level controls are in place. Clusters with PodSecurity admission or OPA/Gatekeeper would independently block some of these (like hostNetwork). Clusters that rely on Argo's Strict mode as the primary enforcement layer are fully exposed. This issue has been patched in versions 3.7.14 and 4.0.5.
Argo has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure
8.1 High
CVSS3