CVE-2026-15416 Details
Description
A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthenticated attacker with network access to the Argo CD repo-server to achieve remote code execution. Under certain conditions, the attacker may then manipulate cached data to deploy malicious Kubernetes resources to managed clusters, potentially resulting in complete cluster compromise.
A remote code execution vulnerability has been identified in the Argo CD repo-server component, which is used in Red Hat OpenShift GitOps. This vulnerability allows an unauthenticated attacker with network access to the repo-server's gRPC interface to execute arbitrary code. The issue arises because the repo-server's internal gRPC service lacks authentication, enabling exploitation by sending crafted requests. Once the code is executed, the attacker can manipulate cached data in Redis to deploy malicious Kubernetes resources, potentially compromising the entire cluster.
Users can update to Argo CD Helm Chart version 10.0.0, which includes the necessary network policy adjustments to protect the repo-server. For those using Argo CD without Helm, it's recommended to manually apply Kubernetes network policies that restrict access to the repo-server and Redis ports.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 11, 2026 | CVE Modified | [email protected] |
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jul 14, 2026 | New CVE Received | [email protected] |