← All Advisories

Argo CD repo-server unauthenticated remote code execution enables manipulation of cached data to compromise managed clusters

Last refreshed2026-09-30

Status: NEW  |  Advisory ID: CVE-2026-15416

Key Details

CVECVE-2026-15416
CVSS Score / Version8.9 (High) / CVSS v3.1
Updated2026-08-11
CVSS VectorCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
CVSS Proseattack vector is adjacent; attack complexity is low; privileges required is low; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is low.
Classified asCWE-306 (Missing Authentication for Critical Function)

What to Know

A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthenticated attacker with network access to the Argo CD repo-server to achieve remote code execution. Under certain conditions, the attacker may then manipulate cached data to deploy malicious Kubernetes resources to managed clusters, potentially resulting in complete cluster compromise. (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-15416
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-15416