Junglewise Threat Intelligence

CVE-2026-43824: Argo CD information disclosure in ServerSideDiff endpoint

CVE-2026-43824 · Severity: high · CVSS 7.7 · Published 2026-05-02

Technologies: Argo Project Argo CD. Vendors: Red Hat, Argo Project.

Executive brief

Argo CD, a popular tool for managing applications on Kubernetes, contains a security flaw that could allow users with limited access to view sensitive information. Specifically, an attacker with read-only permissions can exploit a specific comparison feature to reveal Kubernetes Secrets, such as passwords or API keys, in plain text. This could lead to unauthorized access to other systems or sensitive corporate data managed within the Kubernetes environment.

Technical details

An information disclosure vulnerability exists in the Argo CD ServerSideDiff gRPC/REST endpoint. While Argo CD typically masks Secret data using hideSecretData(), the ServerSideDiff endpoint fails to apply this masking to the PredictedLive and NormalizedLive states in its response. The vulnerability is triggered when an Application has the 'IncludeMutationWebhook=true' annotation, which causes the system to skip the removeWebhookMutation() defense layer that normally strips sensitive fields. An attacker with basic authenticated read-only access can use this endpoint to extract plaintext Kubernetes Secret data from etcd via the Kubernetes API server's Server-Side Apply dry-run mechanism. The issue is patched in versions 3.2.11 and 3.3.9.

Affected products

  • argoproj Argo CD 3.2.0 before 3.2.11, 3.3.0 before 3.3.9
  • Red Hat Red Hat OpenShift GitOps 1

Timeline

  • 2026-05-01: disclosed
  • 2026-05-01: advisory
  • 2026-05-01: patched

References

Related threats