CVE-2026-42880 Details
Description
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kubernetes Secret data from etcd via the Kubernetes API server's Server-Side Apply dry-run mechanism. This issue has been patched in versions 3.2.11 and 3.3.9.
A vulnerability exists in Argo CD versions 3.2.0 prior to 3.2.11 and 3.3.0 prior to 3.3.9, allowing read-only users to extract unmasked Kubernetes Secret data from etcd. This is achieved through the ServerSideDiff endpoint, which improperly handles authorization and data masking. The issue arises because the ServerSideDiff function delivers raw, unmasked data, bypassing Argo CD's usual protections when certain conditions are met. Exploitation is possible if the Secret's data fields are managed by a non-Argo CD field manager, enabling the real values to persist in the response.
Users can upgrade to Argo CD versions 3.2.11 or 3.3.9, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHBA-2026:12433 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:20943 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:20947 | redhat-SADP | |
| https://access.redhat.com/security/cve/CVE-2026-42880 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2467882 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42880.json | redhat-SADP | |
| https://github.com/argoproj/argo-cd/security/advisories/GHSA-3v3m-wc6v-x4x3 | CISA-ADP | ExploitVendor Advisory |
| https://github.com/argoproj/argo-cd/security/advisories/GHSA-3v3m-wc6v-x4x3 | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
| CWE-201 | Insertion of Sensitive Information Into Sent Data | redhat-SADP |
| CWE-212 | Improper Removal of Sensitive Information Before Storage or Transfer | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| argoproj argo cd | >= 3.2.0, < 3.2.11 >= 3.3.0, < 3.3.9 |
CPE
Remediation
| |
Change History
16 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 7, 2026 | CVE Modified | [email protected] |
| Sep 7, 2026 | CVE Modified | redhat-SADP |
| Sep 7, 2026 | CVE Modified | CISA-ADP |
| Aug 17, 2026 | CVE Modified | redhat-SADP |
| Aug 11, 2026 | CVE Modified | redhat-SADP |
| Aug 3, 2026 | CVE Modified | redhat-SADP |
| Jul 27, 2026 | CVE Modified | redhat-SADP |
| Jul 20, 2026 | CVE Modified | redhat-SADP |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jul 14, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 11, 2026 | Initial Analysis | [email protected] |
| May 8, 2026 | CVE Modified | CISA-ADP |
| May 7, 2026 | New CVE Received | [email protected] |