Junglewise Threat Intelligence

CVE-2026-24748: GO-2026-4385 - Kargo's `GetConfig()` and `RefreshResource()` API endpoints allow unauthenticated access in github.com/akuity/kargo

CVE-2026-24748 · Severity: medium · CVSS 4 · Published 2026-02-02

Technologies: github.com/akuity/kargo (Go). Vendors: Go.

Executive brief

Kargo's `GetConfig()` and `RefreshResource()` API endpoints allow unauthenticated access in github.com/akuity/kargo

Affected products

  • Go github.com/akuity/kargo

Related threats