CVE-2026-31892

high Red Hat
CVSS v3 Base Score
9.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Published: March 11, 2026
Last Modified: March 11, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in Argo Workflows. A user with privileges to submit workflows can bypass security settings defined in a WorkflowTemplate by including a `podSpecPatch` field in their workflow submission. This allows them to circumvent restrictions, even when `templateReferencing: Strict` is configured, potentially leading to unauthorized resource access or privilege escalation.

CWE

CWE-807

Affected Products

Red Hat OpenShift AI (RHOAI)

References