Executive brief
Kargo's `GetConfig()` and `RefreshResource()` API endpoints allow unauthenticated access in github.com/akuity/kargo
Affected products
- Go github.com/akuity/kargo
Junglewise Threat Intelligence
CVE-2026-24748 · Severity: medium · CVSS 4 · Published 2026-02-02
Technologies: github.com/akuity/kargo (Go). Vendors: Go.
Kargo's `GetConfig()` and `RefreshResource()` API endpoints allow unauthenticated access in github.com/akuity/kargo