SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-15416

HIGH · CVSS 8.9 EPSS 0.28% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

A vulnerability in Argo CD, utilized by Red Hat OpenShift GitOps, allows unauthenticated attackers with network access to the repo-server to execute remote code. This could enable them to manipulate cached data and deploy malicious resources to Kubernetes clusters, leading to potential complete cluster compromise. Organizations using Kubernetes with Argo CD should prioritize addressing this issue to mitigate the risk of severe security breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15416
Severity
HIGH
CVSS
8.9
EPSS
0.28%
Kubernetes

Original NVD Description

A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthenticated attacker with network access to the Argo CD repo-server to achieve remote code execution. Under certain conditions, the attacker may then manipulate cached data to deploy malicious Kubernetes resources to managed clusters, potentially resulting in complete cluster compromise.