CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-42880

Critical · CVSS 9.6

Argo CD — Missing Authorization and Sensitive Data Exposure via Server-Side Apply dry-run (Secret plaintext leak)

CVSS
9.6
nvd
EPSS
0.51%
41th pct
KEV
No
Class
oss containerizable
CWE-200, CWE-212, CWE-201

Description

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kubernetes Secret data from etcd via the Kubernetes API server's Server-Side Apply dry-run mechanism. This issue has been patched in versions 3.2.11 and 3.3.9.

Search profile — drives PoC discovery

Symbols ServerSideDiffServer-Side Applydry-runServerSideApplyServerSideDiff endpointetcdKubernetes Secretdata-masking
Keywords CVE-2026-42880Argo CDServerSideDiffsecret leakplaintext secretServer-Side Apply dry-runread-only accessKubernetes Secret exposureGHSA-3v3m-wc6v-x4x3missing authorizationdata masking bypassetcd secret extraction
Versions: 3.2.0 to before 3.2.11, 3.3.0 to before 3.3.9

Ranked PoCs (2) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

Affected packages

Bitnami argo-cd 3.2.0 → 3.2.11
Bitnami argo-cd 3.3.0 → 3.3.9
Go github.com/argoproj/argo-cd 0 → ∞
Go github.com/argoproj/argo-cd/v2 0 → ∞
Go github.com/argoproj/argo-cd/v3 3.2.0 → 3.2.11
Go github.com/argoproj/argo-cd/v3 3.3.0 → 3.3.9

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T12:30:14.000Z