CVE-2026-62185
Argo CD Helm Chart before 10.0.0 fails to install network policies by default, allowing any pod on a cluster to access repo-server and other
CVSS
7.6
High
EPSS
0.3%
p20
KEV
—
Exploit Today
6
0-100
Published: Jul 13, 2026 · Last modified: Jul 15, 2026 · CWE-1188
0.3%EPSS · 30 days0.3%
2026-07-142026-07-21
Argo CD Helm Chart before 10.0.0 fails to install network policies by default, allowing any pod on a cluster to access repo-server and other Argo APIs. Attackers can exploit this unrestricted network access through combined attacks to achieve cluster compromise and remote code execution.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-473939.8 CRI—
———PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships a code-generator (`praisonai.deploy.api.generate_api_server_code`) that emits a Flask API server with authentication disabled by default. Users who follow the documented quickstart (`praisonai deploy --type api`) get a server that binds to `0.0.0.0` per the recommended sample YAML, exposes `/chat` and `/agents` endpoints, runs `praisonai.run()` on user-supplied JSON input — LLM orchestration with the API key materials present in the process environment, and does not require any authentication. Versions prior to 4.6.40 still ship the generator with `auth_enabled` defaulting to `False`. The fix shape is opt-in via `APIConfig(auth_enabled=True, auth_token=...)`. Version 4.6.40 fixes the issue.2hCVE-2026-624159.1 CRI—
——0The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated users to upload media assets.2hCVE-2026-600249.8 CRI22.4%
——7The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets.1dCVE-2026-614397.5 HIG17.6%
——5PraisonAI versions before 4.6.78 contain a prompt injection defense misconfiguration where the block threshold defaults to CRITICAL severity, allowing HIGH-level threats to pass through unblocked. Attackers can submit single-vector prompt injection attacks such as instruction overrides or financial manipulation that trigger HIGH severity detection but are logged without blocking, enabling system prompt extraction and unauthorized tool invocations.7dCVE-2026-548004.8 MED4.3%
——1A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application ships with a default configuration that disables all OPC UA security mechanisms. This could allow an attacker to gain unauthorized access and control over critical system functions.12dCVE-2026-144748.8 HIG33.7%
——10A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.20h