cbcvebase.
CVE-2026-42880
published 2026-05-07

CVE-2026-42880: Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing…

PriorityP265critical9.6CVSS 3.1
AVNACLPRLUINSCCHIHAN
EPSS
0.51%
41.3th percentile
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kubernetes Secret data from etcd via the Kubernetes API server's Server-Side Apply dry-run mechanism. This issue has been patched in versions 3.2.11 and 3.3.9.

Affected

17 ranges
VendorProductVersion rangeFixed in
argoprojargo-cd
argoprojargo-cd
argoprojargo_cd>= 3.2.0 < 3.2.113.2.11
argoprojargo_cd>= 3.3.0 < 3.3.93.3.9
github.comargoproj_argo-cd_v3>= 3.2.0 < 3.2.113.2.11
github.comargoproj_argo-cd_v3>= 3.3.0 < 3.3.93.3.9
odf4odf-multicluster-rhel9-operator
openshift-gitops-1argocd-agent-rhel8
openshift-gitops-1argocd-agent-rhel9
openshift-gitops-1argocd-image-updater-rhel8
openshift-gitops-1argocd-image-updater-rhel9
openshift-gitops-1argocd-rhel8
openshift-gitops-1argocd-rhel9_1776942799
openshift-gitops-1gitops-rhel8
openshift-gitops-1gitops-rhel8-operator
openshift-gitops-1gitops-rhel9
openshift-gitops-1gitops-rhel9-operator

Detection & IOCsextracted from sources · hover to see the quote

  • Monitor for unauthorized or anomalous requests to the Argo CD ServerSideDiff endpoint, particularly from accounts with only read-only access, as this endpoint is the attack surface for secret extraction.
  • Alert on Server-Side Apply dry-run API calls to the Kubernetes API server originating from Argo CD service accounts with read-only roles, which may indicate exploitation of CVE-2026-42880.
  • Detect Argo CD deployments running versions 3.2.0–3.2.10 or 3.3.0–3.3.8, which are vulnerable; flag these for immediate patching to 3.2.11 or 3.3.9.
  • ·The vulnerability exists specifically in the ServerSideDiff endpoint; patched versions are 3.2.11 and 3.3.9. Affected version ranges are 3.2.0–3.2.10 and 3.3.0–3.3.8.
  • ·Red Hat products including Red Hat OpenShift GitOps and ODF multicluster operator are confirmed affected, and no mitigation meeting Red Hat's criteria is currently available for those packages.
  • ·This CVE is part of a broader pattern of Argo CD internal surface exposures; defenders should also review CVE-2025-55190 (Git credential disclosure via read-only token) and CVE-2024-31989 (Redis cache poisoning) as related attack chains.

CVSS provenance

nvdv3.19.6CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
vendor_redhat9.6CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.