Insufficiently protected credentials in Argo Workflows - CVE-2026-42295

 

Insufficiently protected credentials in Argo Workflows - CVE-2026-42295

Published: April 23, 2026


Vulnerability identifier: #VU126910
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-42295
CWE-ID: CWE-522
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive credentials.

The vulnerability exists due to insufficiently protected credentials in the workflow executor logging driver when logging artifact operations. A remote privileged user can read workflow pod logs to disclose sensitive credentials.

Any user with Kubernetes RBAC permissions to read pod logs in the workflow namespace can extract artifact repository credentials, including S3, OSS, and GCS credential fields.


Affected software

Argo Workflows

How to mitigate CVE-2026-42295

Install security update from vendor's website.

Argo Workflows - update to 4.0.5

External References

Related Security Bulletins