Database/Container, Kubernetes & orchestration
Argo Events (EventSource / Sensor controller, spec.template.container merge): The controller merges the entire
Impact
The controller merges the entire user-supplied container spec from an EventSource or Sensor custom resource into the pod it creates, so a tenant who can only create those CRs sets securityContext.privileged, adds SYS_ADMIN, and hostPath-mounts the node root. That is node compromise and, through the container runtime socket, cluster compromise - from a namespace-scoped permission that looks harmless. Argo Events is the trigger layer in front of Argo Workflows, so this sits on the same GPU job-submission path.
Who can reach it
Any tenant with create or update rights on EventSource or Sensor CRs in any namespace the controller watches. No cluster-admin, no node access, no direct pod-create permission needed - Pod Security Standards and namespace RBAC are both bypassed.
What to do
Upgrade Argo Events to v1.9.6, which allow-lists which properties under spec.template.container may be set. Restart the controller. Before and after, audit existing EventSource and Sensor objects for privileged securityContext or hostPath volumes - a resource planted earlier keeps running until you delete it.
References
Related entries
- LXD: newline injection in NVIDIA instance config yields code execution as the LXD daemonCVE-2026-63298 · Canonical LXD (NVIDIA instance configuration: nvidia.driver.capabilities, nvidia.require.*)Critical
- RHACM HelmRelease controller: tenant-supplied charts render with the controller's cluster-wide ServiceAccountCVE-2026-67567 · Red Hat Advanced Cluster Management multicloud-operators-subscription (HelmRelease controller)Critical
- Red Hat ACM: unvalidated ocm-managed-cluster annotation lets a hub tenant target any spoke clusterCVE-2026-72526 · Red Hat ACM multicloud-integrations (Argo CD Application propagation controller)Critical
- Dokploy: authenticated members inject shell commands into deploy and backup paths and get host rootCVE-2026-72736 · Dokploy (shell command construction in deploy, backup, git and destination endpoints)Critical
- Dokploy: WebSocket terminals authenticate but never authorize, giving any member a root shell in any containerCVE-2026-72863 · Dokploy WebSocket handlers (container terminal and log streaming)Critical
- Dokploy: swarm endpoints skip the tenant check and inject nodeId into a remote commandCVE-2026-72876 · Dokploy swarm API router (swarm.getNodes / getNodeInfo / getNodeApps / getAppInfos)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.