CVE-2026-15416: Argoproj Argo-Helm

High severity, CVSS 8.9. EPSS: 0.5% chance of exploitation in the next 30 days.

A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthenticated attacker with network access to the Argo CD repo-server to achieve remote code execution. Under certain conditions, the attacker may then manipulate cached data to deploy malicious Kubernetes resources to managed clusters, potentially resulting in complete cluster compromise.

Affected products

  • Argoproj Argo-Helm: before 10.0.0 (fixed in 10.0.0)
  • Red Hat Red Hat Openshift Data Foundation 4
  • Red Hat Red Hat Openshift Gitops
  • Red Hat Red Hat Openshift Gitops 1.19: before 1785149260 (fixed in 1785149260); before 1785171339 (fixed in 1785171339)

Published 2026-07-14. Last modified 2026-08-11.