Unauthenticated Exposure in Argo Rollouts Dashboard by ArgoProj
CVE-2026-82277
9.3CRITICAL
What is CVE-2026-82277?
The Argo Rollouts dashboard prior to version 1.10.0 is vulnerable as it binds to all interfaces, allowing attackers on the same network to execute sensitive mutating operations like PromoteRollout, AbortRollout, RestartRollout, SetRolloutImage, UndoRollout, and RetryRollout across all namespaces accessible to the operator's kubeconfig without requiring authentication, authorization, or CSRF protection. This flaw presents significant risks for Kubernetes environments, enabling unauthorized modifications and control over deployment processes.
Affected Version(s)
argo-rollouts 0 <= 1.10.0
