Skip to content
Red HatCVE-2026-15416

Red Hat Argo CD: remote code execution

High8.9CVE-2026-15416 · Published Jul 14, 2026 · updated Aug 11, 2026

A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthenticated attacker with network access to the Argo CD repo-server to achieve remote code execution. Under certain conditions, the attacker may then manipulate cached data to deploy malicious Kubernetes resources to managed clusters, potentially resulting in complete cluster compromise.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat OpenShift GitOps
Product
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
Red Hat Openshift Data Foundation 4
Product
all versionsNo fix yet
argo-helm
Product
< 10.0.010.0.0
Details and references

More Red Hat advisories

All Red Hat
Advisory
A flaw was found in libsoup's WebSocket implementation
High7.5Jul 14
Red Hat libsoup: denial of service
High7.5Jul 14
Red Hat libsoup: denial of service
Medium5.9Jul 14
Red Hat libsoup: out-of-bounds read
Medium6.5Jul 14
Red Hat Enterprise Linux 10: denial of service
Medium5.9Jul 14
Red Hat open5gs: out-of-bounds read
High8.6Jul 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.