{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aargoprojargo_workflows4.1.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:argoproj:argo_workflows:4.1.0:*:*:*:*:*:*:*","cpe:2.3:a:argoproj:argo_workflows:4.1.1:*:*:*:*:*:*:*","cpe:2.3:a:argoproj:argo_workflows:4.1.2:*:*:*:*:*:*:*","cpe:2.3:a:argoproj:argo_workflows:4.1.3:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.7,"id":"CVE-2026-93991"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Argo Workflows (4.1.0-4.1.3)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","cloud","authorization-bypass"],"_cs_type":"advisory","_cs_vendors":["Argo Project"],"content_html":"\u003cp\u003eArgo Workflows versions 4.1.0 through 4.1.3 are affected by an authorization bypass vulnerability (CVE-2026-93991) within the ListArchivedWorkflows function. The vulnerability stems from an inadequate application of cluster-scoped access reviews when users provide specific field selectors during an API request. Specifically, when a request includes a metadata.namespace field selector utilizing the NotEquals operator, the system fails to restrict the result set to the user's authorized namespace. This flaw allows an authenticated attacker possessing only namespace-scoped list permissions to successfully perform unauthorized data exfiltration. Impacted organizations may see exposure of sensitive information stored in archived workflows, including spec arguments, parameter values, and metadata annotations from namespaces they do not legitimately manage.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to unauthorized information disclosure of workflow configurations across a Kubernetes cluster. This can expose sensitive secrets, environment-specific parameters, and architectural details contained within workflow specs that should be protected by RBAC, potentially aiding in further lateral movement or privilege escalation within the cloud environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade Argo Workflows to the latest patched version immediately.\u003c/li\u003e\n\u003cli\u003eAudit Kubernetes RBAC policies to ensure minimal list permissions are applied to namespace-scoped service accounts.\u003c/li\u003e\n\u003cli\u003eReview API access logs for anomalous usage of metadata.namespace field selectors with negation operators.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-20T00:15:55Z","date_published":"2026-09-20T00:15:55Z","id":"https://feed.craftedsignal.io/briefs/2026-09-argo-workflows-auth-bypass/","summary":"Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows allowing unauthorized access to workflow metadata via crafted namespace field selectors.","title":"Authorization Bypass in Argo Workflows ListArchivedWorkflows","url":"https://feed.craftedsignal.io/briefs/2026-09-argo-workflows-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:argoproj:argo_workflows:4.1.1:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}