CVE-2026-82456
Medium
Elevated severity or exploit probability.
CVSS base
10.0
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
1.7%
76.6th percentile
CISA KEV
Not listed
Weakness / dates
CWE-1327
Published 2026-08-29 · modified 2026-09-23
Description
argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the operator's stored token to create applications, request syncs, and modify Argo CD resources.
References
- https://github.com/argoproj-labs/mcp-for-argocd
- https://github.com/argoproj-labs/mcp-for-argocd/security/advisories/GHSA-rp45-5x3v-48mr
- https://www.vulncheck.com/advisories/argocd-mcp-0.8.0-authentication-bypass-via-unauthenticated-http
- https://github.com/argoproj-labs/mcp-for-argocd/security/advisories/GHSA-rp45-5x3v-48mr