logo

Argo CD ServerSideDiff Flaw Allows Attackers to Extract Kubernetes Secrets

ID: 9323f54c-e30a-5b4f-8fd1-2c2c89dd7701

STIX ID: report--9323f54c-e30a-5b4f-8fd1-2c2c89dd7701

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

Author: Divya

...
...

A critical Argo CD vulnerability (CVE-2026-42880, CVSS 9.6) in the ServerSideDiff endpoint can bypass data-masking and allow authenticated users with minimal read privileges to extract real Kubernetes Secret values (tokens, credentials, API keys, TLS certs) from etcd when the compare-options annotation with mutation webhooks is enabled. A Python proof-of-concept automates the extraction via grpc-web; maintainers released patched versions 3.3.9 and 3.2.11 to address the issue—organizations should upgrade immediately and review their CD pipeline webhook configurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.