CVE-2026-82456

Source
https://cve.org/CVERecord?id=CVE-2026-82456
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82456.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-82456
Aliases
  • GHSA-rp45-5x3v-48mr
Published
2026-08-29T13:47:57.447Z
Modified
2026-08-31T03:45:44.935964393Z
Severity
  • 10.0 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H CVSS Calculator
Summary
argocd-mcp 0.8.0 Authentication Bypass via Unauthenticated HTTP
Details

argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCDAPITOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the operator's stored token to create applications, request syncs, and modify Argo CD resources.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82456.json",
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-1327"
    ]
}
References

Affected packages

Git / github.com/argoproj-labs/mcp-for-argocd

Affected ranges

Type
GIT
Repo
https://github.com/argoproj-labs/mcp-for-argocd
Events
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0.8.0"
        },
        {
            "fixed": "0.9.0"
        }
    ]
}

Affected versions

v0.*
v0.8.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-82456.json"