PT-2026-24700 · Unknown · Argo Workflows

Masamuneee

·

Publicado

2026-03-11

·

Atualizado

2026-05-13

·

CVE-2026-28229

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Argo Workflows versions prior to 4.0.2 and 3.7.11
Description Argo Workflows, an open source container-native workflow engine for Kubernetes, has an issue where Workflow templates endpoints allow any client to retrieve WorkflowTemplates and ClusterWorkflowTemplates. A request with an Authorization: Bearer nothing token can expose sensitive template content, including embedded Secret manifests. The issue stems from how informers use the server’s rest config, reading using server service account privileges. A proof-of-concept demonstrates the ability to leak template data, including secrets, artifact locations, service account usage, environment variables, and resource manifests.
Recommendations Update to Argo Workflows version 4.0.2 or 3.7.11.

Exploit

Correção

Incorrect Authorization

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BIT-ARGO-WORKFLOWS-2026-28229
CVE-2026-28229
GHSA-56PX-HM34-XQJ5
GO-2026-4678
SUSE-SU-2026:1042-1

Produtos afetados

Argo Workflows