CVE-2026-43824Disclosure

LOWCVSS 7.7 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-212CWE-312

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 12 mentions across 4 observed days
  • Momentum state: declining

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 11 signals
  • Disclosure: 5 classified signals
  • General: 3 classified signals
  • Peaked 3d ago at 8 mentions (2026-05-02); latest day: 1
  • 12 total mentions across 4 days

Deep dive

Activity timeline12 mentions / 4d
02468Mentions · 2026-05-02: 8Mentions · 2026-05-04: 1Mentions · 2026-05-07: 2Mentions · 2026-05-14: 1PoC Mentioned / Linked · 2026-05-02: 1Patch / Workaround · 2026-05-02: 3Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-05-07: 1Technical Details · 2026-05-02: 7Technical Details · 2026-05-04: 1Technical Details · 2026-05-07: 2Technical Details · 2026-05-14: 105-0205-0405-0705-14
Signal classification4 categories
Disclosure
541.7%
General
325.0%
Patch
325.0%
PoC
18.3%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-05-028
Disclosure5General1Patch1PoC1
2026-05-041
Patch1
2026-05-072
General1Patch1
2026-05-141
General1
Full discourse12 posts
  • Vito Botta@vitobotta
    Patch

    Read-only access in ArgoCD and you can extract every plaintext Kubernetes secret in the cluster. That's CVE-2026-43824 / GHSA-3v3m-wc6v-x4x3, and it's bad. The ServerSideDiff endpoint strips secret masking when IncludeMutationWebhook=true is set on an Application. The handler calls a Kubernetes SSA dry-run, gets raw Secret data back from etcd, and flies it straight into the API response. No masking. No auth check beyond "are you logged in." Base64-encoded, but that's not encryption obvipously. Versions affected: ArgoCD 3.2.0 through 3.3.8. Fixed in 3.2.11 and 3.3.9. The one saving some people: IncludeMutationWebhook isn't on by default. But if you've ever turned it on to debug mutating webhooks, you may have left a door open. If you're running ArgoCD in any serious environment, this is an upgrade you do today situation. Or at the very least, grep your Applications for that annotation and check who has read access. https://github.com/argoproj/argo-cd/security/advisories/GHSA-3v3m-wc6v-x4x3

    Post summary

    The advisory discloses that ArgoCD versions 3.2.0–3.3.8 leak plaintext Kubernetes secrets when a debugging flag is enabled, and it recommends upgrading to patched releases.

    10041240
    1.1K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Argo CD | High Severity | CVE-2026-43824 May expose Kubernetes secrets via ServerSideDiff. Review configs & restrict access. https://github.com/argoproj/argo-cd/security/advisories/GHSA-3v3m-wc6v-x4x3 #Kubernetes #CVE #CloudSecurity

    Post summary

    A new high‑severity CVE (CVE‑2026‑43824) for Argo CD is announced, highlighting potential exposure of Kubernetes secrets through ServerSideDiff and recommending configuration review and access restriction.

    00051155
    237 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-43824: Argo CD Secret Disclosure Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04gCFLR0

    Post summary

    The text provides a general overview of CVE-2026-43824 as a secret disclosure bug in Argo CD without indicating available PoCs, exploits, active exploitation, or patches.

    0000035
    30 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Critical #ArgoCD vulnerability (CVE-2026-43824) exposes Kubernetes Secrets. Immediate patching to versions 3.3.9 or 3.2.11 is essential. Link: https://thedailytechfeed.com/critical-security-flaw-in-argo-cd-exposes-kubernetes-secrets-urgent-patch-advised/ #ArgoCD #Kubernetes #Secrets #Vulnerability #CVE #Security #Cybersecurity #DevOps #Patching #Exploit #Exposure #Cluster #Infrastructure #Containers #GitOps #Breach #Risk #Update #Protection #Compliance

    Post summary

    The post warns about CVE‑2026‑43824 exposing Kubernetes Secrets and urgently urges users to apply the available patches to versions 3.3.9 or 3.2.11.

    0000052
    307 followersView on X
  • DailyCVE@dailycve
    General

    🔴 Argo CD, Authorization Bypass, #CVE-2026-43824 (Critical) https://dailycve.com/argo-cd-authorization-bypass-cve-2026-43824-critical/

    Post summary

    The tweet announces a critical authorization bypass vulnerability in Argo CD (CVE-2026-43824) but provides no detailed exploit, evidence of abuse, mitigations, or proof‑of‑concept.

    0000034
    196 followersView on X
  • JulietSecurity@JulietSecurity
    PoC

    Argo CD CVE-2026-43824: did read-only app access overlap with managed Kubernetes Secrets? In our labs, IncludeMutationWebhook=true was the key condition. Fixed 3.2.11 / 3.3.9 masked the same path. https://juliet.sh/blog/we-tested-argocd-cve-2026-43824-serversidediff-secret-exposure

    Post summary

    The post reports testing of Argo CD CVE‑2026‑43824, pointing out a configuration-based vulnerability (IncludeMutationWebhook=true) and cites a blog for details, while noting that specific patch versions exist. No active exploitation or functional exploit is referenced.

    0000069
    18 followersView on X
  • JulietSecurity@JulietSecurity
    Patch

    Argo CD users: CVE-2026-43824 is worth checking today. Affected: 3.2.0-3.3.8 Fixed: 3.2.11 / 3.3.9 Upgrade first. Then inventory the exposure path: - who has application get - apps with IncludeMutationWebhook=true - managed apps containing Kubernetes Secrets

    Post summary

    The post informs Argo CD users of CVE-2026‑43824, specifies affected and fixed versions, and urges an upgrade while advising inventory of exposed resources such as applications with IncludeMutationWebhook enabled and Kubernetes Secrets.

    0000051
    18 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-43824 📊 Severity: 7.7 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-43824 #CVE-2026-43824 #CVE #High #CyberSecurity #InfoSec https://t.co/AAGKb7HhQ9

    Post summary

    The tweet announces a new CVE (CVE-2026-43824) with a severity of 7.7 but provides no technical details, PoC, or mitigation information.

    0000060
    151 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-43824 In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data. https://www.cve.org/CVERecord?id=CVE-2026-43824 ----- Traducción: CVE-2026-43824 En Argo CD 3.2.0 antes de 3.2.11 y 3.3.0 antes de 3.3… http://infoflow.cloud`

    Post summary

    The post discloses CVE-2026-43824, a ServerSideDiff vulnerability in Argo CD 3.2.0‑3.2.10 and 3.3.0‑3.3.8 that permits reading Kubernetes Secret data. It lists affected and fixed versions but provides no PoC, exploit code, or claims of active exploitation.

    0000038
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-43824 In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data. https://www.cve.org/CVERecord?id=CVE-2026-43824

    Post summary

    The Tweet announces CVE-2026-43824, noting that before specific Argo CD releases an insecure ServerSideDiff feature can expose cleartext Kubernetes secrets, but it contains no PoC, exploit, active‑use claims, fixes, or false‑positive notes.

    00000262
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-43824 Cleartext Kubernetes Secret Data Exposure in Argo CD ServerSideDiff https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-43824

    Post summary

    The text announces a new vulnerability in Argo CD that exposes Kubernetes secret data, but provides no PoC, exploit, or mitigation details.

    0000070
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-43824 In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data. CVSS 7.7 Full analysis → https://sec.kaitan.id/cves/CVE-2026-43824 #Kubernetes #CyberSecurity #InfoSec

    Post summary

    The text announces a high‑severity vulnerability (CVE‑2026‑43824) affecting specific Argo CD versions, detailing the flaw and its impact.

    0000052
    458 followersView on X

Explore more