CVE-2026-62185 HIGH

CVE-2026-62185: Argo CD Helm Chart < 10.0.0 Missing Network Policy RCE

Vendor Argoproj
Product argo-helm
Weakness CWE-1188
Published July 13, 2026
Last update July 13, 2026

CVSS base score

8.6/10
Attack vector Adjacent
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Argo CD Helm Chart before 10.0.0 fails to install network policies by default, allowing any pod on a cluster to access repo-server and other Argo APIs. Attackers can exploit this unrestricted network access through combined attacks to achieve cluster compromise and remote code execution.

Key dates

02Disclosure timeline

July 13, 2026 CVE published