Executive brief
Argo Workflows is an automation engine used to run parallel jobs on Kubernetes clusters. A security flaw allows users with basic workflow creation permissions to bypass 'Strict' security restrictions, potentially gaining unauthorized access to the underlying host network or sensitive service accounts. This could lead to data exposure or the ability to run unauthorized tasks with elevated privileges, depending on the cluster's overall security configuration.
Technical details
An authorization bypass exists in Argo Workflows due to an incomplete fix for a previous vulnerability. While the system correctly blocks 'podSpecPatch' when 'templateReferencing: Strict' is enabled, it fails to validate other 'WorkflowSpec' fields that are merged during pod creation. An attacker with 'create Workflow' permissions can inject fields such as 'hostNetwork', 'serviceAccountName', 'securityContext', or 'tolerations' into a workflow that references a hardened template. Because the 'JoinWorkflowSpec' logic gives priority to user-defined fields when the template relies on defaults, these overrides are applied to the resulting Kubernetes pods. This allows for privilege escalation, such as scheduling pods on control-plane nodes or mounting service account tokens. The issue is patched in versions 3.7.14 and 4.0.5.
Affected products
- argoproj Argo Workflows < 3.7.14, >= 4.0.0, < 4.0.5
Timeline
- 2026-04-23: advisory: GitHub Security Advisory published
- 2026-04-23: patched: Versions 3.7.14 and 4.0.5 released
- 2026-05-09: disclosed: CVE-2026-42296 published to NVD