Record summary

CVE-2026-31892 has a selected CVSS score of 8.9 (high).

Description

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 2.9.0 to before 4.0.2 and 3.7.11, A user who can submit Workflows can completely bypass all security settings defined in a WorkflowTemplate by including a podSpecPatch field in their Workflow submission. This works even when the controller is configured with templateReferencing: Strict, which is specifically documented as a mechanism to restrict users to admin-approved templates. The podSpecPatch field on a submitted Workflow takes precedence over the referenced WorkflowTemplate during spec merging and is applied directly to the pod spec at creation time with no security validation. This vulnerability is fixed in 4.0.2 and 3.7.11.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 11, 2026 · Source: CVE List

Affected products and versions

Showing 12 of 16
ProductSourceVersion rangeStatus

Red Hat OpenShift AI (RHOAI)

Browse Red Hat / Red Hat OpenShift AI (RHOAI)rhoai/odh-ml-pipelines-api-server-v2-rhel8

Default status: unaffected

CVE ListVersion data not supplied

Red Hat OpenShift AI (RHOAI)

Browse Red Hat / Red Hat OpenShift AI (RHOAI)rhoai/odh-ml-pipelines-driver-rhel8

Default status: unaffected

CVE ListVersion data not supplied

Red Hat OpenShift AI (RHOAI)

Browse Red Hat / Red Hat OpenShift AI (RHOAI)rhoai/odh-ml-pipelines-launcher-rhel8

Default status: unaffected

CVE ListVersion data not supplied

Red Hat OpenShift AI (RHOAI)

Browse Red Hat / Red Hat OpenShift AI (RHOAI)rhoai/odh-ml-pipelines-persistenceagent-v2-rhel8

Default status: unaffected

CVE ListVersion data not supplied

Red Hat OpenShift AI (RHOAI)

Browse Red Hat / Red Hat OpenShift AI (RHOAI)rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel8

Default status: unaffected

CVE ListVersion data not supplied

Red Hat OpenShift AI 2.25

Browse Red Hat / Red Hat OpenShift AI 2.25rhoai/odh-data-science-pipelines-argo-argoexec-rhel9

Default status: affected

CVE List1776740558 to < *unaffected

Red Hat OpenShift AI 2.25

Browse Red Hat / Red Hat OpenShift AI 2.25rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9

Default status: affected

CVE List1776740640 to < *unaffected

Red Hat OpenShift AI 2.25

Browse Red Hat / Red Hat OpenShift AI 2.25rhoai/odh-ml-pipelines-api-server-v2-rhel9

Default status: affected

CVE List1776740726 to < *unaffected

Red Hat OpenShift AI 2.25

Browse Red Hat / Red Hat OpenShift AI 2.25rhoai/odh-ml-pipelines-driver-rhel9

Default status: affected

CVE List1776740379 to < *unaffected

Red Hat OpenShift AI 2.25

Browse Red Hat / Red Hat OpenShift AI 2.25rhoai/odh-ml-pipelines-launcher-rhel9

Default status: affected

CVE List1776740386 to < *unaffected

Red Hat OpenShift AI 2.25

Browse Red Hat / Red Hat OpenShift AI 2.25rhoai/odh-ml-pipelines-persistenceagent-v2-rhel9

Default status: affected

CVE List1776740351 to < *unaffected

Red Hat OpenShift AI 2.25

Browse Red Hat / Red Hat OpenShift AI 2.25rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel9

Default status: affected

CVE List1776740366 to < *unaffected

References

7