Executive brief
Argo CD is a tool used to automate the deployment of applications into Kubernetes clusters. A security flaw in its repository server component allows an attacker who has gained a foothold in the same network to execute unauthorized commands. This could allow an attacker to deploy malicious software across the entire cluster, potentially leading to a total takeover of the organization's container infrastructure and data.
Technical details
A vulnerability exists in the Argo CD repo-server's GenerateManifest gRPC endpoint due to missing authentication (CWE-306). An attacker with network access to the repo-server can provide malicious KustomizeOptions, specifically manipulating BuildOptions or BinaryPath, to achieve remote code execution within the repo-server pod. This is particularly exploitable when Argo CD is installed via Helm charts where network policies are disabled by default (versions < 10.0.0), allowing any pod in the cluster to reach the gRPC service. By combining this RCE with Redis cache manipulation, an attacker can deploy unauthorized Kubernetes resources, leading to full cluster compromise. The issue is addressed in Argo CD Helm Chart version 10.0.0 by enabling network policies by default.
Affected products
- argoproj Argo CD Helm Chart < 10.0.0
- Red Hat Red Hat OpenShift GitOps 1
- Red Hat Red Hat OpenShift Data Foundation 4 4
Timeline
- 2025-01: disclosed: Vulnerability reported to maintainers by Synacktiv
- 2026-06-29: advisory: GitHub Security Advisory published for argo-helm
- 2026-07-14: advisory: CVE-2026-15416 published by Red Hat
References
- https://github.com/argoproj/argo-helm
- https://access.redhat.com/downloads/content/package-browser/
- https://access.redhat.com/security/cve/CVE-2026-15416
- https://bugzilla.redhat.com/show_bug.cgi?id=2496732
- https://github.com/argoproj/argo-helm/commit/0f245ab
- https://github.com/argoproj/argo-helm/security/advisories/GHSA-47m3-95c7-g2g8
- https://thehackernews.com/2026/07/unpatched-argo-cd-repo-server-flaw.html