Improper access control in Argo Workflows - CVE-2026-28229

 

Improper access control in Argo Workflows - CVE-2026-28229

Published: April 23, 2026


Vulnerability identifier: #VU126904
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-28229
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in workflow template and cluster workflow template endpoints when handling requests to retrieve templates. A remote attacker can send a request with a crafted bearer token to disclose sensitive information.

Exposed template content may include embedded Secret manifests, artifact locations, service account usage, environment variables, and resource manifests.


Affected software

Argo Workflows

How to mitigate CVE-2026-28229

Install security update from vendor's website.

Argo Workflows - addressed in versions 3.7.11, 4.0.2

External References

Related Security Bulletins