PT-2026-37193 · Unknown · Argo Workflows

·

CVE-2026-42295

·

Published

2026-05-04

·

Updated

2026-07-30

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Argo Workflows versions 4.0.0 through 4.0.4
Description The workflow executor logs artifact repository credentials in plaintext during artifact operations. This occurs because the logging driver passes the entire ArtifactDriver struct to the structured logger, exposing sensitive fields such as AccessKey, SecretKey, SessionToken, and ServerSideCustomerKey for S3, AccessKey, SecretKey, and SecurityToken for OSS, and ServiceAccountKey for GCS. Any user with Kubernetes RBAC permissions to read workflow pod logs can extract these credentials.
Recommendations Update to version 4.0.5.

Exploit

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ARGO-WORKFLOWS-2026-42295
CVE-2026-42295
GHSA-7VF8-2CR6-54MF
GO-2026-5235
OPENSUSE-SU-2026:21483-1

Affected Products

Argo Workflows