CVE-2026-42297: CWE-862: Missing Authorization in argoproj argo-workflows
Argo Workflows versions 4.0.0 up to but not including 4.0.5 contain a missing authorization vulnerability in the Sync Service's ConfigMap-backed provider. This flaw allows any authenticated user, including those with fake Bearer tokens, to perform create, read, update, and delete operations on Kubernetes ConfigMaps that control synchronization limits. The issue has been fixed in version 4.0.5.
AI Analysis
Technical Summary
CVE-2026-42297 is a missing authorization vulnerability (CWE-862) in the Sync Service ConfigMap-backed provider of Argo Workflows from version 4.0.0 to before 4.0.5. The service performs zero authorization checks on all CRUD operations on Kubernetes ConfigMaps containing synchronization limits. This allows any authenticated user, even those using fake Bearer tokens, to manipulate these ConfigMaps. The vulnerability has been addressed and patched in version 4.0.5.
Potential Impact
Exploitation of this vulnerability allows any authenticated user to create, read, update, and delete critical Kubernetes ConfigMaps related to synchronization limits in Argo Workflows. This could lead to unauthorized modification of workflow synchronization behavior, potentially disrupting workflow orchestration or causing denial of service conditions. The CVSS 4.0 score is 8.5 (high severity), reflecting network attack vector, low attack complexity, no privileges required, no user interaction, and high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
A fix is available in Argo Workflows version 4.0.5. Users should upgrade to version 4.0.5 or later to remediate this vulnerability. The Red Hat advisory linked confirms the patch availability. Until upgraded, restrict access to authenticated users and monitor for unauthorized ConfigMap modifications.
CVE-2026-42297: CWE-862: Missing Authorization in argoproj argo-workflows
Description
Argo Workflows versions 4.0.0 up to but not including 4.0.5 contain a missing authorization vulnerability in the Sync Service's ConfigMap-backed provider. This flaw allows any authenticated user, including those with fake Bearer tokens, to perform create, read, update, and delete operations on Kubernetes ConfigMaps that control synchronization limits. The issue has been fixed in version 4.0.5.
CVSS v4.0
Score 8.5high
Affected software
pkg:github/argoproj/argo-workflowsRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-42297 is a missing authorization vulnerability (CWE-862) in the Sync Service ConfigMap-backed provider of Argo Workflows from version 4.0.0 to before 4.0.5. The service performs zero authorization checks on all CRUD operations on Kubernetes ConfigMaps containing synchronization limits. This allows any authenticated user, even those using fake Bearer tokens, to manipulate these ConfigMaps. The vulnerability has been addressed and patched in version 4.0.5.
Potential Impact
Exploitation of this vulnerability allows any authenticated user to create, read, update, and delete critical Kubernetes ConfigMaps related to synchronization limits in Argo Workflows. This could lead to unauthorized modification of workflow synchronization behavior, potentially disrupting workflow orchestration or causing denial of service conditions. The CVSS 4.0 score is 8.5 (high severity), reflecting network attack vector, low attack complexity, no privileges required, no user interaction, and high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
A fix is available in Argo Workflows version 4.0.5. Users should upgrade to version 4.0.5 or later to remediate this vulnerability. The Red Hat advisory linked confirms the patch availability. Until upgraded, restrict access to authenticated users and monitor for unauthorized ConfigMap modifications.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-04-26T12:13:55.552Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-42297","vendor":"Red Hat"}]
Threat ID: 69ffe1b2cbff5d8610ead449
Added to database: 05/10/2026, 01:38:58 UTC
Last enriched: 06/30/2026, 21:57:24 UTC
Last updated: 06/30/2026, 21:57:24 UTC
Views: 95
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.