CVE-2026-42880CRITICAL 9.6EPSS p29.6%
CVE-2026-42880CVE-2026-42880
Description
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint that allows an attacker with read-only access to extract plaintext Kubernetes Secret data from etcd via the Kubernetes API server's Server-Side Apply dry-run mechanism. This issue has been patched in versions 3.2.11 and 3.3.9.
Scoring
| CVSS 3.1 | 9.6 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
| EPSS | 0.38% probability of exploitation · percentile 29.6% · 2026-06-19T12:03:05Z |
| Published | 2026-05-07 |
| Last modified | 2026-05-11 |
Underlying weaknesses· 2
References
2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Exposure of Sensitive Information to an Unauthorized Actorcwe-200 | 0% | live |
| Weakness | Improper Removal of Sensitive Information Before Storage or Transfercwe-212 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.