Authentication Bypass in Argo CD MCP Tool by Argo Project
CVE-2026-82456

10CRITICAL

Key Information:

Vendor
CVE Published:
29 August 2026

What is CVE-2026-82456?

The argocd-mcp 0.8.0 version possesses a critical security flaw that enables an attacker to access the HTTP transport bound to all network interfaces without requiring credentials. If the ARGOCD_API_TOKEN is configured, malicious entities within network reach can leverage this vulnerability to execute commands typically gated by authentication, allowing full control over the tool's functionalities, including the creation of applications, triggering synchronizations, and altering Argo CD resources.

Affected Version(s)

argocd-mcp 0.8.0 < 0.9.0

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

shmulc8
.