CVE-2026-82456

Published: Ago 29, 2026 Last Modified: Ago 29, 2026
ExploitDB:
Other exploit source:
Google Dorks:
CRITICAL 10,0
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
CRITICAL 10,0
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: changed
Confidentiality: high
Integrity: high
Availability: high

Description

AI Translation Available

argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the operator's stored token to create applications, request syncs, and modify Argo CD resources.

1327

Binding to an Unrestricted IP Address

Incomplete
Common Consequences
Security Scopes Affected:
Availability
Potential Impacts:
Dos: Amplification
Applicable Platforms
Languages: Other
Technologies: Web Server, Client Server, Cloud Computing
View CWE Details
https://github.com/argoproj-labs/mcp-for-argocd
https://github.com/argoproj-labs/mcp-for-argocd/security/advisories/GHSA-rp45-5…
https://www.vulncheck.com/advisories/argocd-mcp-0.8.0-authentication-bypass-via…