Missing Authorization in Argo Workflows - #VU126907
Published: April 23, 2026
Argo Workflows
Detailed vulnerability description
The vulnerability allows a remote user to read and modify synchronization limits and related ConfigMaps.
The vulnerability exists due to improper access control in the Sync Service ConfigMap-backed provider in server/sync/sync_cm.go when handling create, read, update, and delete sync limit requests. A remote user can send crafted API requests to read and modify synchronization limits and related ConfigMaps.
Exploitation requires Argo Server to be running with --auth-mode=server.