PT-2026-37356 · Argo Cd · Argo Cd

Published

2026-05-06

·

Updated

2026-05-06

·

CVE-2026-42880

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Argo CD versions 3.2.0 through 3.2.10 Argo CD versions 3.3.0 through 3.3.8
Description Read-only users can extract plaintext Kubernetes secrets through the use of Server-Side Diffs.
Recommendations Update versions 3.2.0 through 3.2.10 to v3.3.9. Update versions 3.3.0 through 3.3.8 to v3.3.9.

Related Identifiers

CVE-2026-42880

Affected Products

Argo Cd