Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Nebojsaj1726

#31738of 55,133
8.5Total CVSS
Vulnerabilities · 1
PT-2026-37195
8.5
2026-05-04
Unknown · Argo Workflows · CVE-2026-42297
**Name of the Vulnerable Software and Affected Versions** Argo Workflows versions 4.0.0 through 4.0.4 **Description** The Sync Service's ConfigMap-backed provider in `server/sync/sync cm.go` lacks authorization checks for all create, read, update, and delete (CRUD) operations. This allows any authenticated user, including those utilizing fake Bearer tokens, to perform these operations on Kubernetes ConfigMaps that store synchronization limits. **Recommendations** Update to version 4.0.5.