216.73.216.226

CVE-2026-42297

· Published 09/05/2026 04:16 · Modified 09/05/2026 04:16

Labels: CVE-2026-42297 2026-05-09CVE-2026-42297CWE-862[email protected]

Essential information

Published
09/05/2026 04:16
Modified
09/05/2026 04:16
Author
Creator
CVSS
8.5 HIGH (v3) 8.5 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version 4.0.5, the Sync Service's ConfigMap-backed provider (server/sync/sync_cm.go) performs zero authorization checks on all CRUD operations (create, read, update, delete). Any authenticated user — including those using fake Bearer tokens — can create, read, update, and delete Kubernetes ConfigMaps containing synchronization limits. This issue has been patched in version 4.0.5.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
argoproj / argo workflows cpe:2.3:a:argoproj:argo_workflows:4.0.0-4.0.4:*:*:*:*:*:*:*

References