Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-62185— Argo CD Helm Chart < 10.0.0 Missing Network Policy RCE

CVSS 7.6 · High EPSS 0.28% · P20

Affected Version Matrix 2

VendorProductVersion RangeStatus
argoprojargo-helm< 10.0.0affected
10.0.0unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-62185

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Argo CD Helm Chart < 10.0.0 Missing Network Policy RCE
Source: NVD (National Vulnerability Database)
Vulnerability Description
Argo CD Helm Chart before 10.0.0 fails to install network policies by default, allowing any pod on a cluster to access repo-server and other Argo APIs. Attackers can exploit this unrestricted network access through combined attacks to achieve cluster compromise and remote code execution.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Source: NVD (National Vulnerability Database)
Vulnerability Type
不安全的默认资源初始化
Source: NVD (National Vulnerability Database)
Vulnerability Title
argoproj Argo Helm Charts 配置错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
argoproj Argo Helm Charts是argoproj组织开源的一个由社区维护的 Helm Chart 集合,用于在 Kubernetes 上快速部署 Argo 项目。 argoproj Argo Helm Charts 10.0.0之前版本存在配置错误漏洞,该漏洞源于默认情况下未安装网络策略,允许集群中的任何 pod 访问 repo-server 和其他 Argo APIs。攻击者可通过组合攻击利用此不受限制的网络访问,实现集群破解和远程代码执行。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
argoprojargo-helm 0 ~ 10.0.0 -

II. Public POCs for CVE-2026-62185

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium
Qwen3.6-35B-A3B · 11142 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-62185

登录查看更多情报信息。

Vendor Advisories for CVE-2026-62185 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-62185

No comments yet


Leave a comment