Improper access control in Argo Workflows - #VU126903

 

Improper access control in Argo Workflows - #VU126903

Published: July 22, 2021 / Updated: April 23, 2026


Vulnerability identifier: #VU126903
CSH Severity: Medium
CVSS v4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code on the Kubernetes cluster.

The vulnerability exists due to improper access control in Argo Server when the user interface is exposed to the internet while using --auth-mode=server. A remote user can access the exposed interface to execute arbitrary code on the Kubernetes cluster.

Only deployments using Argo Server with --auth-mode=server and an internet-exposed UI are vulnerable.


Affected software

Argo Workflows

Remediation

Install security update from vendor's website.

Argo Workflows - update to 3.0.0

External References

Related Security Bulletins