PT-2026-37193 · Unknown · Argo Workflows

Masamuneee

·

Published

2026-05-04

·

Updated

2026-05-12

·

CVE-2026-42295

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Argo Workflows versions 4.0.0 through 4.0.4
Description The workflow executor logs artifact repository credentials in plaintext during artifact operations. This occurs because the logging driver passes the entire ArtifactDriver struct to the structured logger, exposing sensitive fields such as AccessKey, SecretKey, SessionToken, and ServerSideCustomerKey for S3, AccessKey, SecretKey, and SecurityToken for OSS, and ServiceAccountKey for GCS. Any user with Kubernetes RBAC permissions to read workflow pod logs can extract these credentials.
Recommendations Update to version 4.0.5.

Exploit

Fix

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

BIT-ARGO-WORKFLOWS-2026-42295
CVE-2026-42295
GHSA-7VF8-2CR6-54MF

Affected Products

Argo Workflows