CVE-2026-82456
argocd-mcp 0.8.0 Authentication Bypass via Unauthenticated HTTP
CVSS Score
10.0
EPSS Score
0.0%
EPSS Percentile
0th
argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the operator's stored token to create applications, request syncs, and modify Argo CD resources.
| CWE | CWE-1327 |
| Vendor | argoproj-labs |
| Product | argocd-mcp |
| Published | Aug 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for argoproj-labs argocd-mcp
Be the first to know when new critical vulnerabilities affecting argoproj-labs argocd-mcp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
argoproj-labs / argocd-mcp
0.8.0 < 0.9.0
References
Credits
๐ shmulc8