CVE-2026-43824 Details
Description
In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.
A vulnerability in Argo CD versions 3.2.0 prior to 3.2.11 and 3.3.0 prior to 3.3.9 allows users with read-only access to extract unmasked Kubernetes Secret data from etcd via the Kubernetes API server's Server-Side Apply dry-run mechanism. This issue arises because the ServerSideDiff endpoint fails to properly mask Secret data, exposing sensitive information such as service account tokens, TLS certificates, database credentials, and API keys. The vulnerability is particularly exploitable on applications with a specific annotation that disables a built-in defense mechanism.
Users can upgrade to Argo CD versions 3.3.9 or 3.2.11, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 2, 2026CISA-ADP
Assessed May 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-43824 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2464613 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43824.json | redhat-SADP | |
| https://github.com/argoproj/argo-cd/security/advisories/GHSA-3v3m-wc6v-x4x3 | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/argoproj/argo-cd/security/advisories/GHSA-3v3m-wc6v-x4x3 | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-212 | Improper Removal of Sensitive Information Before Storage or Transfer | [email protected] |
| CWE-312 | Cleartext Storage of Sensitive Information | redhat-SADP |
Affected Products
| Product | Versions |
|---|---|
| Argo CD | >= 3.2.0, <= 3.3.8 (semver) |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 4, 2026 | CVE Modified | CISA-ADP |
| May 2, 2026 | New CVE Received | [email protected] |
Volerion