Authorization bypass through user-controlled key in Argo Workflows - CVE-2026-93991
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper authorization in the ListArchivedWorkflows handler when processing metadata.namespace!= field selectors. A remote user can submit a crafted archived-workflow list request to disclose sensitive information.
Exploitation requires namespace-scoped permission to list workflows in a namespace controlled by the user.