Beveiligingsadvies

CVE-2026-82456

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-29 13:47:57
Laatst bijgewerkt 2026-09-02 18:00:04
Toegewezen door VulnCheck
CVSS-score 10.0
Status PUBLISHED

Beschrijving

argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the operator's stored token to create applications, request syncs, and modify Argo CD resources.