CVE-2026-42296: Argo Workflows Incomplete Workflowspec Restriction Checkcve-2026-42296-argo-workflows-incomplete-workflowspec-restriction-check
Incomplete authorization enforcement for workflowTemplateRef restriction mode: only HasPodSpecPatch() is validated, leaving hostNetwork, serviceAccountName, securityContext, tolerations, automountServiceAccountToken, volumes, and other security-sensitive WorkflowSpec fields unchecked before the spec merge. A user with workflow-create permission can inject th