PT-2026-95875 · Unknown · Argo Workflows
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Argo Workflows versions 4.1.0 through 4.1.3
Description
An authorization bypass exists in the
ListArchivedWorkflows function. The issue occurs when the metadata.namespace field selector utilizes the NotEquals operator, causing a failure to apply cluster-scoped access reviews. Users with namespace-scoped list permissions can employ a negated namespace field selector to retrieve archived workflows from other namespaces, potentially exposing annotations, parameter values, and spec arguments.Recommendations
Update Argo Workflows to a version later than 4.1.3.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Argo Workflows