CVE-2026-15416 - CERT CVE
ID CVE-2026-15416
Sažetak A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthenticated attacker with network access to the Argo CD repo-server to achieve remote code execution. Under certain conditions, the attacker may then manipulate cached data to deploy malicious Kubernetes resources to managed clusters, potentially resulting in complete cluster compromise.
Reference
CVSS
Base: 8.9
Impact: 6.0
Exploitability:2.3
Pristup
VektorSloženostAutentikacija
ADJACENT_NETWORK LOW LOW
Impact
PovjerljivostCjelovitostDostupnost
HIGH HIGH LOW
CVSS vektor CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Zadnje važnije ažuriranje 15-07-2026 - 15:16
Objavljeno 14-07-2026 - 09:16