Authentication Bypass in Argo CD MCP Tool by Argo Project
CVE-2026-82456
10CRITICAL
What is CVE-2026-82456?
The argocd-mcp 0.8.0 version possesses a critical security flaw that enables an attacker to access the HTTP transport bound to all network interfaces without requiring credentials. If the ARGOCD_API_TOKEN is configured, malicious entities within network reach can leverage this vulnerability to execute commands typically gated by authentication, allowing full control over the tool's functionalities, including the creation of applications, triggering synchronizations, and altering Argo CD resources.
Affected Version(s)
argocd-mcp 0.8.0 < 0.9.0
