logo

GitOps Security Breach: Critical 9.6 CVSS Argo CD Flaw Exposes Plaintext Kubernetes Secrets

ID: a51f9d9c-6910-5812-8b8c-56427ef687ec

STIX ID: report--a51f9d9c-6910-5812-8b8c-56427ef687ec

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-05-06

Date Updated: 2026-05-08

Author: Ddos

...
...

Argo CD is affected by CVE-2026-42880 (CVSS 9.6): a Server-Side Diff handling flaw can leak plaintext Kubernetes Secrets to authenticated low-privileged users when the argocd.argoproj.io/compare-options:IncludeMutationWebhook=true annotation is set; Argo CD released patches in versions 3.3.9 and 3.2.11 and organizations using GitOps should upgrade immediately to prevent exposure of service tokens, TLS certificates, API keys, and database credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.