{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-15416","assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","state":"PUBLISHED","assignerShortName":"redhat","dateReserved":"2026-07-10T14:49:39.682Z","datePublished":"2026-07-14T08:56:29.942Z","dateUpdated":"2026-08-11T00:38:39.224Z"},"containers":{"cna":{"title":"Argo-cd: argo cd unauthenticated remote code execution in repo-server via generatemanifest grpc endpoint","metrics":[{"other":{"content":{"value":"Important","namespace":"https://access.redhat.com/security/updates/classification/"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"LOW","baseScore":8.9,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L","version":"3.1"},"format":"CVSS"}],"descriptions":[{"lang":"en","value":"A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthenticated attacker with network access to the Argo CD repo-server to achieve remote code execution. Under certain conditions, the attacker may then manipulate cached data to deploy malicious Kubernetes resources to managed clusters, potentially resulting in complete cluster compromise."}],"affected":[{"vendor":"argoproj","product":"argo-helm","versions":[{"status":"affected","version":"0","lessThan":"10.0.0","versionType":"semver"}],"packageName":"argo-helm","collectionURL":"https://github.com/argoproj/argo-helm","defaultStatus":"unaffected"},{"vendor":"Red Hat","product":"Red Hat OpenShift GitOps 1.19","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift-gitops-1/argocd-rhel8","defaultStatus":"affected","versions":[{"version":"1785149260","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:openshift_gitops:1.19::el8"]},{"vendor":"Red Hat","product":"Red Hat OpenShift GitOps 1.19","collectionURL":"https://catalog.redhat.com/software/containers/","packageName":"openshift-gitops-1/gitops-rhel8-operator","defaultStatus":"affected","versions":[{"version":"1785171339","lessThan":"*","versionType":"rpm","status":"unaffected"}],"cpes":["cpe:/a:redhat:openshift_gitops:1.19::el8"]},{"vendor":"Red Hat","product":"Red Hat Openshift Data Foundation 4","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"odf4/odf-multicluster-rhel9-operator","defaultStatus":"unaffected","cpes":["cpe:/a:redhat:openshift_data_foundation:4"]},{"vendor":"Red Hat","product":"Red Hat OpenShift GitOps","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-gitops-1/argocd-agent-rhel8","defaultStatus":"unknown","cpes":["cpe:/a:redhat:openshift_gitops:1"]},{"vendor":"Red Hat","product":"Red Hat OpenShift GitOps","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-gitops-1/argocd-agent-rhel9","defaultStatus":"unaffected","cpes":["cpe:/a:redhat:openshift_gitops:1"]},{"vendor":"Red Hat","product":"Red Hat OpenShift GitOps","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-gitops-1/argocd-image-updater-rhel8","defaultStatus":"affected","cpes":["cpe:/a:redhat:openshift_gitops:1"]},{"vendor":"Red Hat","product":"Red Hat OpenShift GitOps","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-gitops-1/argocd-image-updater-rhel9","defaultStatus":"unaffected","cpes":["cpe:/a:redhat:openshift_gitops:1"]},{"vendor":"Red Hat","product":"Red Hat OpenShift GitOps","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-gitops-1/argocd-rhel9","defaultStatus":"unknown","cpes":["cpe:/a:redhat:openshift_gitops:1"]},{"vendor":"Red Hat","product":"Red Hat OpenShift GitOps","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-gitops-1/gitops-operator-bundle","defaultStatus":"affected","cpes":["cpe:/a:redhat:openshift_gitops:1"]},{"vendor":"Red Hat","product":"Red Hat OpenShift GitOps","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-gitops-1/gitops-rhel8","defaultStatus":"affected","cpes":["cpe:/a:redhat:openshift_gitops:1"]},{"vendor":"Red Hat","product":"Red Hat OpenShift GitOps","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-gitops-1/gitops-rhel9","defaultStatus":"unaffected","cpes":["cpe:/a:redhat:openshift_gitops:1"]},{"vendor":"Red Hat","product":"Red Hat OpenShift GitOps","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"openshift-gitops-1/gitops-rhel9-operator","defaultStatus":"unaffected","cpes":["cpe:/a:redhat:openshift_gitops:1"]}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2026:52857","name":"RHSA-2026:52857","tags":["vendor-advisory","x_refsource_REDHAT"]},{"url":"https://access.redhat.com/security/cve/CVE-2026-15416","tags":["vdb-entry","x_refsource_REDHAT"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2496732","name":"RHBZ#2496732","tags":["issue-tracking","x_refsource_REDHAT"]},{"url":"https://github.com/argoproj/argo-helm/commit/0f245ab"},{"url":"https://github.com/argoproj/argo-helm/security/advisories/GHSA-47m3-95c7-g2g8"},{"url":"https://thehackernews.com/2026/07/unpatched-argo-cd-repo-server-flaw.html"},{"url":"https://www.synacktiv.com/en/publications/caught-in-the-octopus-trap-unauthenticated-rce-in-argo-cd-with-codeql"}],"datePublic":"2026-07-01T00:00:00.000Z","problemTypes":[{"descriptions":[{"cweId":"CWE-306","description":"Missing Authentication for Critical Function","lang":"en","type":"CWE"}]}],"x_redhatCweChain":"CWE-306: Missing Authentication for Critical Function","workarounds":[{"lang":"en","value":"Limit network access to the Argo CD repo-server gRPC endpoint to trusted internal components using Kubernetes NetworkPolicy or equivalent network access controls. Do not expose the repo-server outside the cluster or to untrusted networks. Restrict access to the associated Redis service and update to a fixed version once one becomes available."}],"timeline":[{"lang":"en","time":"2026-07-03T00:00:00.000Z","value":"Reported to Red Hat."},{"lang":"en","time":"2026-07-01T00:00:00.000Z","value":"Made public."}],"providerMetadata":{"orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat","dateUpdated":"2026-08-11T00:38:39.224Z"},"x_generator":{"engine":"cvelib 1.8.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-07-15T14:39:38.453802Z","id":"CVE-2026-15416","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-07-15T14:39:52.411Z"}}]}}