CVE-2026-42880Disclosure(argoproj / argo_cd)

LOWCVSS 9.6 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch argoproj argo_cd systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kubernetes Secret data from etcd via the Kubernetes API server's Server-Side Apply dry-run mechanism. This issue has been patched in versions 3.2.11 and 3.3.9.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-212CWE-201

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • argo_cd

Threat summary

  • Patch or workaround signal is available
  • 19 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 16 signals
  • Disclosure: 11 classified signals
  • General: 2 classified signals
  • Peaked 6d ago at 6 mentions (2026-05-06); latest day: 3
  • 19 total mentions across 7 days

Affected systems

Vendors
Products
argo_cd

Deep dive

Activity timeline19 mentions / 7d
02356Mentions · 2026-05-06: 6Mentions · 2026-05-07: 1Mentions · 2026-05-08: 3Mentions · 2026-05-10: 1Mentions · 2026-05-13: 4Mentions · 2026-05-15: 1Mentions · 2026-06-08: 3Patch / Workaround · 2026-05-06: 3Patch / Workaround · 2026-05-08: 2Patch / Workaround · 2026-05-13: 1Patch / Workaround · 2026-06-08: 1Technical Details · 2026-05-06: 4Technical Details · 2026-05-07: 1Technical Details · 2026-05-08: 3Technical Details · 2026-05-10: 1Technical Details · 2026-05-13: 4Technical Details · 2026-05-15: 1Technical Details · 2026-06-08: 205-0605-0705-0805-1005-1305-1506-08
Signal classification3 categories
Disclosure
1157.9%
Patch
631.6%
General
210.5%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-05-066
Disclosure2General1Patch3
2026-05-071
Disclosure1
2026-05-083
Disclosure2Patch1
2026-05-101
Disclosure1
2026-05-134
Disclosure2General1Patch1
2026-05-151
Disclosure1
2026-06-083
Disclosure2Patch1
Full discourse19 posts
  • Gray Hats@the_yellow_fall
    Patch

    A critical 9.6 CVSS flaw in Argo CD (CVE-2026-42880) allows read-only users to extract plaintext Kubernetes secrets via Server-Side Diffs. Patch to v3.3.9 now! #ArgoCD #Kubernetes #GitOps #CloudNative #InfoSec #CyberSecurity #K8s #SecretLeak #CVE202642880 https://securityonline.info/argo-cd-critical-secret-leak-cve-2026-42880-kubernetes-security/ https://t.co/qvYmv2G0FO

    Post summary

    Argo CD CVE‑2026‑42880 is a 9.6‑scored flaw that lets read‑only users retrieve Kubernetes secrets through server‑side diffs, and a patch is now available in v3.3.9.

    040104721
    12.5K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    Argo CDに重大(Critical)な脆弱性。CVE-2026-42880はCVSSスコア9.8の機微データ露出。ServerSideDiffエンドポイントにhideSecretData()が適用されていない。通常、認証後のArgo CDユーザが一般的に保有している"get"アクセスで悪用可能。修正版提供あり。 https://securityonline.info/argo-cd-critical-secret-leak-cve-2026-42880-kubernetes-security/

    Post summary

    The article highlights a critical data‑exposure flaw in Argo CD (CVE‑2026‑42880) with a CVSS of 9.8 and notes that a patch has been released, but no PoC or evidence of active exploitation is provided.

    00063925
    7.6K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Argo CD の脆弱性 CVE-2026-42880 が FIX:データマスキングの不具合による Kubernetes Secret の抽出 https://iototsecnews.jp/2026/05/06/argo-cd-serversidediff-flaw-allows-attackers-to-extract-kubernetes-secrets/ Kubernetes 上でのアプリ展開を自動化するツール Argo CD に見つかった、極めて深刻な脆弱性を解説する記事です。この問題の原因は、サーバ側で設定の差分を計算する ServerSideDiff という機能において、本来は隠すべきパスワードやトークンなどの機密情報をマスクしない状態でレスポンスしてしまう不備にあります。その結果、 Kubernetes の管理用データが保管されている etcd から、生のシークレット・データが引き出されてしまいます。ご利用のチームは、ご注意ください。 #ArgoCD #CVE202642880 #Vulnerability

    Post summary

    The article reports a severe CVE-2026-42880 in Argo CD that improperly exposes Kubernetes secrets via ServerSideDiff, but it does not provide a patch, exploit code, or evidence of active attacks.

    02001151
    491 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The Kubernetes Secret Leak: CVE-2026-42880 Argo CD Authorization Bypass Exposes etcd to Read-Only Users. The attack requires no authentication escalation, no complex exploits, and no public PoC—just a crafted request to a normally benign endpoint to trigger secret exposure.

    Post summary

    CVE‑2026‑42880 is an authorization bypass that lets read‑only users access etcd secrets via a crafted request to a benign endpoint; no PoC, exploit code, active exploitation, or patch is reported.

    1000052
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    TL;DR A critical authorization bypass (CVE-2026-42880, CVSS 9.6) in Argo CD's ServerSideDiff endpoint allows attackers with read-only access to extract plaintext Kubernetes secrets directly from etcd. Versions 3.2.0–3.2.10 and 3.3.0–3.3.8 are vulnerable. Patch immediately…

    Post summary

    The post announces a critical CVE-2026-42880 in Argo CD’s ServerSideDiff endpoint, details the vulnerability type and affected versions, and urges immediate patching.

    1000039
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Sources TheHackerWire – Argo CD CVE-2026-42880: Read-Only Access Exposes Kubernetes Secrets TheHackerWire – CVE-2026-42880 Vulnerability Database The Kubernetes Secret Leak: CVE-2026-42880 Argo CD Authorization Bypass Exposes etcd to Read-Only Users

    Post summary

    The text announces a new CVE (CVE-2026-42880) affecting Argo CD, highlighting an authorization bypass that could expose Kubernetes secrets.

    1000046
    258 followersView on X
  • DevOps Daily@thedevopsdaily
    Disclosure

    📝 Argo CD CVE-2026-42880: When Read-Only Means Read-Everything-Including-Secrets A critical Argo CD bug (CVSS 9.6, disclosed May 7) lets any authenticated user pull plaintext Kubern https://devops-daily.com/posts/argocd-cve-2026-42880-serversidediff-secret-leak #DevOps #Kubernetes

    Post summary

    A newly disclosed critical Argo CD vulnerability (CVSS 9.6) allows authenticated users to retrieve all plaintext secrets. The text provides vulnerability details but no PoC, exploit, or patch information.

    0001074
    95 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-42880 CVSS: 9.6 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes.

    Post summary

    CVE-2026-42880 is disclosed with a critical CVSS score and severity, but no exploit details, PoC, or patch information are provided.

    1000036
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVSS 9.6 CRITICAL · CVE-2026-42880 · 9.6 → 3.2.0 CVE: CVE-2026-42880 CVSS: 9.6 (3.1) — CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory

    Post summary

    The snippet presents only the CVSS score and severity classification for CVE-2026-42880, with no additional context on exploitation or remediation.

    1000046
    210 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42880 Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authoriza… https://www.cve.org/CVERecord?id=CVE-2026-42880

    Post summary

    The text announces CVE-2026-42880, a missing authorization vulnerability affecting Argo CD versions 3.2.0‑3.2.10 and 3.3.0‑3.3.8.

    00010188
    57.5K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-42880 Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.… CVSS 9.6 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-42880 #Kubernetes #CyberSecurity #InfoSec

    Post summary

    A new critical CVE-2026-42880 affecting Argo CD versions 3.2.0 to 3.2.11 and 3.3.x has been disclosed, with a CVSS score of 9.6 and no patch available yet.

    0001062
    515 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Critical #ArgoCD vulnerability disclosed CVE-2026-42880 allows read-only users to expose plaintext Kubernetes Secrets via ServerSideDiff. Affected: • Argo CD 3.2.0–3.2.10 • Argo CD 3.3.0–3.3.8 Patch immediately. #Kubernetes #DevSecOps ()

    Post summary

    A critical CVE exposing Kubernetes Secrets has been disclosed for specific Argo CD versions, and the vendor has urged an immediate patch.

    0001070
    149 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    https://lyrie.ai/research/research/cve-2026-42880-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The advisory announces CVE‑2026‑42880, documents its technical details, and advises applying the available patch.

    0000029
    210 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical exposure of sensitive information #vulnerability in #Argo CD delivery tool for #Kubernetes. #CVE-2026-42880 CVSS: 9.6. This could allow an attacker with minimal privileges to extract plain text Kubernetes secrets. #Patch #Patch #Patch

    Post summary

    The notice discusses a CVE-2026-42880 vulnerability in Argo CD with a CVSS score of 9.6, which permits attackers with minimal privileges to retrieve Kubernetes secrets, and notes that a patch is available.

    00000222
    7.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42880 Missing Authorization in Argo CD ServerSideDiff Endpoint Allows Secret Data Extraction https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42880

    Post summary

    The post announces the disclosure of CVE-2026‑42880, a missing‑authorization flaw in Argo CD’s ServerSideDiff endpoint that permits secret data extraction.

    0000062
    4.0K followersView on X
  • Vignesh_Pravin@VigneshVic23698
    Disclosure

    CVE-2026-42880: Argo CD Flaw Exposes Kubernetes Secrets https://thecybrdef.com/cve-2026-42880-argo-cd-kubernetes-secrets-exposure/ #CVE202642880 #Cybernews #Cybersecurity

    Post summary

    The linked article announces CVE-2026-42880, a flaw in Argo CD that can expose Kubernetes secrets, without providing PoC, exploitation details, or mitigation guidance.

    0000036
    2 followersView on X
  • Crypto Master💎 Arichain@Vijaykiran0987
    Disclosure

    CVE-2026-42880: Argo CD Flaw Exposes Kubernetes Secrets https://thecybrdef.com/cve-2026-42880-argo-cd-kubernetes-secrets-exposure/ #CVE202642880 #Cybernews #Cybersecurity

    Post summary

    The text announces a newly disclosed flaw (CVE‑2026‑42880) in Argo CD that exposes Kubernetes secrets, but does not provide PoC, exploit code, or patch details.

    0000035
    64 followersView on X
  • selva@SelvaKtm2
    Disclosure

    CVE-2026-42880: Argo CD Flaw Exposes Kubernetes Secrets https://thecybrdef.com/cve-2026-42880-argo-cd-kubernetes-secrets-exposure/ #CyberSecurity #Kubernetes #CloudSecurity #DevSecOps #InfoSec #Vulnerability #ZeroDay #DataBreach #SecurityAlert #ThreatIntelligence https://t.co/CxI2MRECKn

    Post summary

    The tweet announces a newly disclosed CVE (CVE‑2026‑42880) that affects Argo CD, potentially exposing Kubernetes secrets.

    0000050
    5 followersView on X
  • cybersecuritypath@cybrsecpath
    General

    CVE-2026-42880: Argo CD Flaw Exposes Kubernetes Secrets https://thecybrdef.com/cve-2026-42880-argo-cd-kubernetes-secrets-exposure/ #CyberSecurity #Kubernetes #CloudSecurity #DevSecOps #InfoSec #Vulnerability #ZeroDay #DataBreach #SecurityAlert #ThreatIntelligence

    Post summary

    The post announces a new CVE involving Argo CD and Kubernetes secrets but provides no further technical details, PoC links, exploit information, or remediation steps.

    0000050
    9 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appargoprojargo_cd---

Explore more