CVE-2026-62185: Argoproj Argo-Helm
High severity, CVSS 7.6. EPSS: 0.5% chance of exploitation in the next 30 days.
Argo CD Helm Chart before 10.0.0 fails to install network policies by default, allowing any pod on a cluster to access repo-server and other Argo APIs. Attackers can exploit this unrestricted network access through combined attacks to achieve cluster compromise and remote code execution.
Affected products
- Argoproj Argo-Helm: before 10.0.0 (fixed in 10.0.0)
Published 2026-07-13. Last modified 2026-07-15.