Junglewise Threat Intelligence

CVE-2026-82456: Argo CD MCP unauthenticated remote code execution

CVE-2026-82456 · Severity: critical · CVSS 10 · Published 2026-08-29

Vendors: Argo Project.

Executive brief

Argo CD MCP is a server that enables AI assistants to manage Argo CD application deployments through natural language. Version 0.8.0 listens on all network interfaces without authentication, allowing any attacker on the network to invoke deployment commands using the operator's stored Argo CD token. An attacker can create malicious applications, trigger deployments, and gain code execution on the managed Kubernetes cluster.

Technical details

The vulnerability is a combination of unsafe network binding and missing authentication. The HTTP transport in argocd-mcp 0.8.0 binds to 0.0.0.0 (all network interfaces) without Host or Origin validation. When ARGOCD_API_TOKEN is configured, the server accepts MCP session initialization requests without requiring the caller to present credentials; it falls back to the environment variable token instead. Once authenticated to the MCP session, an attacker can call create_application (to define a malicious deployment) and sync_application (to trigger it), both executed with the operator's stored Argo CD API token. No user interaction or authentication is required; network reachability is sufficient. Patched in version 0.9.0.

Affected products

  • Argo Project argocd-mcp 0.8.0

Timeline

  • 2026-08-11: disclosed
  • 2026-08-29: published
  • 2026: patched: Version 0.9.0

References