<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:argoproj:argo_workflows:4.1.1:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aargoprojargo_workflows4.1.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 20 Sep 2026 00:15:55 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aargoprojargo_workflows4.1.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in Argo Workflows ListArchivedWorkflows</title><link>https://feed.craftedsignal.io/briefs/2026-09-argo-workflows-auth-bypass/</link><pubDate>Sun, 20 Sep 2026 00:15:55 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-argo-workflows-auth-bypass/</guid><description>Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows allowing unauthorized access to workflow metadata via crafted namespace field selectors.</description><content:encoded><![CDATA[<p>Argo Workflows versions 4.1.0 through 4.1.3 are affected by an authorization bypass vulnerability (CVE-2026-93991) within the ListArchivedWorkflows function. The vulnerability stems from an inadequate application of cluster-scoped access reviews when users provide specific field selectors during an API request. Specifically, when a request includes a metadata.namespace field selector utilizing the NotEquals operator, the system fails to restrict the result set to the user's authorized namespace. This flaw allows an authenticated attacker possessing only namespace-scoped list permissions to successfully perform unauthorized data exfiltration. Impacted organizations may see exposure of sensitive information stored in archived workflows, including spec arguments, parameter values, and metadata annotations from namespaces they do not legitimately manage.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation leads to unauthorized information disclosure of workflow configurations across a Kubernetes cluster. This can expose sensitive secrets, environment-specific parameters, and architectural details contained within workflow specs that should be protected by RBAC, potentially aiding in further lateral movement or privilege escalation within the cloud environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade Argo Workflows to the latest patched version immediately.</li>
<li>Audit Kubernetes RBAC policies to ensure minimal list permissions are applied to namespace-scoped service accounts.</li>
<li>Review API access logs for anomalous usage of metadata.namespace field selectors with negation operators.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>cloud</category><category>authorization-bypass</category></item></channel></rss>