Junglewise Threat Intelligence

CVE-2026-42880: Argo CD information disclosure in ServerSideDiff endpoint

CVE-2026-42880 · Severity: critical · CVSS 9.6 · Published 2026-05-07

Technologies: github.com/argoproj/argo-cd (Go), github.com/argoproj/argo-cd/v3 (Go), Argo Project Argo CD, github.com/argoproj/argo-cd/v2 (Go). Vendors: Go, Red Hat, Argo Project.

Executive brief

Argo CD, a tool used to automate the deployment of applications to Kubernetes, contains a vulnerability that could allow an attacker to steal sensitive credentials. By exploiting a flaw in how the system compares different versions of application configurations, a user with basic read-only access can bypass security protections to view plaintext secrets, such as passwords or API keys. This could lead to unauthorized access to other parts of the corporate infrastructure or sensitive data stored in the Kubernetes environment.

Technical details

A vulnerability exists in the Argo CD ServerSideDiff gRPC/REST endpoint due to missing authorization checks and a failure to mask sensitive data. The endpoint utilizes the Kubernetes API server's Server-Side Apply (SSA) dry-run mechanism to calculate differences between resource states. While Argo CD typically employs a defense layer to strip non-managed fields and mask secrets, this protection is bypassed when the application is configured with the 'IncludeMutationWebhook=true' annotation. An authenticated attacker with read-only permissions can invoke this endpoint to receive raw, unmasked secret values from etcd. The issue is patched in Argo CD versions 3.2.11 and 3.3.9.

Affected products

  • argoproj Argo CD 3.2.0 to 3.2.10, 3.3.0 to 3.3.8
  • Red Hat Red Hat OpenShift GitOps 1.19, 1.20

Timeline

  • 2026-04-30: patched: Red Hat released initial bug fix advisory
  • 2026-05-01: advisory: GitHub Security Advisory published by maintainers
  • 2026-05-07: disclosed: NVD publication date

References

Related threats