securityonline.info 7 Oct 2026, 16:56 UTC

Argo CD Patches Four Critical Flaws That Could Expose Secrets and Clusters

Argo CD Patches Four Critical Flaws That Could Expose Secrets and Clusters
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

ARGO CD has issued patches for four critical vulnerabilities, each rated CVSS 9.9, affecting the repo-server and AppProject controls across multiple releases. The flaws include Kustomize Helm config home, Kustomize remote ref, Jsonnet file read, and an AppProject hook bypass tracked as CVE-2026-77459. The release notes confirm patched versions: v3.5.4, v3.4.10, v3.3.15 and v3.6.0-rc2.

While maintainers say there is no confirmed exploitation in the wild, the issues collectively enable both code execution and access to sensitive data if exploited.

Details on how the flaws work are drawn from the advisories. The Kustomize Helm config home flaw allows a crafted Helm-driven kustomization to run a command with the repo-server’s privileges, potentially exposing repository credentials. The Kustomize remote ref issue can cause Git to execute a command within the repo-server by passing a crafted version value, even if the repo-server egress is blocked.

The Jsonnet file read flaw enables an importer to open paths readable by the repo-server, potentially exposing environment variables, service-account tokens, private keys and repository credentials. The AppProject bypass (CVE-2026-77459) lets a user who can push to the backing Git repository create hooks the project would normally block, potentially granting cluster-wide access upon deletion of an application.

If upgrading immediately isn’t possible, advisories offer partial mitigations, including removing --enable-helm from Kustomize builds, disabling Jsonnet in the ConfigMap, pinning Kustomize to older versions (e.g., 4.5.7), and narrowly limiting who can push to Git or delete applications. However, these workarounds may degrade functionality, and patching remains the recommended full fix.

View full article

Article by CyberSIXT