Junglewise Threat Intelligence

CVE-2026-82277: Argo Rollouts dashboard authentication bypass in rollout operations

CVE-2026-82277 · Severity: critical · CVSS 9.8 · Published 2026-08-28

Executive brief

Argo Rollouts is a Kubernetes-native tool for managing progressive deployments. The dashboard server binds to all network interfaces and exposes critical deployment operations (promote, abort, restart, and image updates) without requiring authentication or authorization checks. An attacker on the same network can invoke these operations across all namespaces, allowing them to disrupt deployments, trigger unintended rollouts, or modify application images in production.

Technical details

The vulnerability is an authentication and authorization bypass in the Argo Rollouts dashboard server. The dashboard binds to 0.0.0.0 (all interfaces) and exposes HTTP handlers for mutating rollout operations (PromoteRollout, AbortRollout, RestartRollout, SetRolloutImage, UndoRollout, RetryRollout) without validating authentication credentials, authorization claims, or CSRF tokens. An unauthenticated attacker on the same network can send crafted HTTP requests to invoke these operations against any rollout across all Kubernetes namespaces that the operator's kubeconfig has access to. The server.go file contains the vulnerable handler implementations that lack authentication middleware. No credential or user interaction is required; a network-reachable position is sufficient for exploitation.

Affected products

  • Argo Rollouts through 1.10.0

Timeline

  • 2026-08-28: disclosed

References