PT-2026-24700 · Unknown · Argo Workflows

Masamuneee

·

Published

2026-03-11

·

Updated

2026-05-13

·

CVE-2026-28229

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Argo Workflows versions prior to 4.0.2 and 3.7.11
Description Argo Workflows, an open source container-native workflow engine for Kubernetes, has an issue where Workflow templates endpoints allow any client to retrieve WorkflowTemplates and ClusterWorkflowTemplates. A request with an Authorization: Bearer nothing token can expose sensitive template content, including embedded Secret manifests. The issue stems from how informers use the server’s rest config, reading using server service account privileges. A proof-of-concept demonstrates the ability to leak template data, including secrets, artifact locations, service account usage, environment variables, and resource manifests.
Recommendations Update to Argo Workflows version 4.0.2 or 3.7.11.

Exploit

Fix

Incorrect Authorization

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ARGO-WORKFLOWS-2026-28229
CVE-2026-28229
GHSA-56PX-HM34-XQJ5
GO-2026-4678
SUSE-SU-2026:1042-1

Affected Products

Argo Workflows