GitOps Security Breach: Critical 9.6 CVSS Argo CD Flaw Exposes Plaintext Kubernetes Secrets
ID: a51f9d9c-6910-5812-8b8c-56427ef687ec
STIX ID: report--a51f9d9c-6910-5812-8b8c-56427ef687ec
Feed Name: securityonline.info
Threat Score
Argo CD is affected by CVE-2026-42880 (CVSS 9.6): a Server-Side Diff handling flaw can leak plaintext Kubernetes Secrets to authenticated low-privileged users when the argocd.argoproj.io/compare-options:IncludeMutationWebhook=true annotation is set; Argo CD released patches in versions 3.3.9 and 3.2.11 and organizations using GitOps should upgrade immediately to prevent exposure of service tokens, TLS certificates, API keys, and database credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
