Improper access control in Argo Workflows - CVE-2026-28229
Published: April 23, 2026
Argo Workflows
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in workflow template and cluster workflow template endpoints when handling requests to retrieve templates. A remote attacker can send a request with a crafted bearer token to disclose sensitive information.
Exposed template content may include embedded Secret manifests, artifact locations, service account usage, environment variables, and resource manifests.