logo

Argo CD’s ServerSideDiff Vulnerability Enables Kubernetes Secret Extraction

ID: c4d1a7cc-05cf-5a08-a04f-8e290e9efc05

STIX ID: report--c4d1a7cc-05cf-5a08-a04f-8e290e9efc05

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-05-06

Date Updated: 2026-05-11

Author: Abinaya

...
...

A critical CVE-2026-43824 vulnerability in Argo CD’s ServerSideDiff handler can return unmasked Kubernetes Secrets (CVSS 9.6), enabling any authenticated low-privileged user to extract plaintext secret values from affected Argo CD versions 3.2.0–3.3.8; patches (3.3.9, 3.2.11) and mitigations (remove IncludeMutationWebhook=true, tighten RBAC, monitor ServerSideDiff API usage) are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.