CRITICAL🇵🇱 Wersja polska

CVE-2026-42880

CVSS 9.6v3.1pub. 2026-05-07upd. 2026-08-17

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kubernetes Secret data from etcd via the Kubernetes API server's Server-Side Apply dry-run mechanism. This issue has been patched in versions 3.2.11 and 3.3.9.

🤖 AI Analysis
How it works

The vulnerability results from a lack of proper authorization and data masking in the ServerSideDiff endpoint. This endpoint uses the Server-Side Apply dry-run mechanism available in the Kubernetes API Server. An attacker with read-only privileges can send a properly crafted request to this endpoint, which indirectly retrieves and returns data from Kubernetes Secret objects in plain text from the etcd storage, bypassing sensitive value masking mechanisms.

Impact

An attacker can gain full access to data stored in Kubernetes Secret objects in plaintext form, such as passwords, tokens, API keys, or certificates. The breach affects the confidentiality and integrity of data stored in the Kubernetes cluster.

Mitigation & patch

Argo CD should be updated to version 3.2.11 or 3.3.9, in which the vulnerability has been fixed. Patches are available in the official project repository according to the provided references.

Who is affected

Argo CD in versions from 3.2.0 to 3.2.10 inclusive and from 3.3.0 to 3.3.8 inclusive.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
  • Argoproj Argo Cd

    APP
    Argoproj
    3.2.0 – 3.2.11 (excl.)3.3.0 – 3.3.9 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Container
CWE
References

Related vulnerabilities

CVE-2025-55190CRITICAL9.9PL ✓same product

Argo CD: nieuprawniony dostęp do poświadczeń repozytoriów przez API token

CVE-2025-47933CRITICAL9.0PL ✓same product

XSS w Argo CD — wykonanie akcji w imieniu ofiary via API

CVE-2024-31989CRITICAL9.0PL ✓same product

Argo CD: nieautoryzowany dostęp do Redis umożliwia privilege escalation

CVE-2024-21652CRITICAL9.8PL ✓same product

Argo CD: Ominięcie ochrony przed brute force logowania

CVE-2024-28175CRITICAL9.0PL ✓same product

Argo CD: XSS w adnotacjach linków umożliwia przejęcie uprawnień