Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-82277: Argo Rollouts dashboard lets anyone change deployments
CVE-2026-82277 · published 6 days ago
Summary
Versions of Argo Rollouts dashboard up to 1.10.0 listen on every network address and do not require a login or other checks. Because of this, anyone on the same network can start, stop, restart, or alter rollout processes for any project the dashboard can see. Upgrade to a newer release and restrict network access to trusted users or systems.
Original advisory text
Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection. Attackers on the same network can i...
Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection. Attackers on the same network can invoke PromoteRollout, AbortRollout, RestartRollout, SetRolloutImage, UndoRollout, and RetryRollout operations across all namespaces accessible to the operator's kubeconfig.
Severity
9.3
Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published28 Aug 2026
Updated3 Sep 2026
First seen29 Aug 2026
Sources
CVE-2026-82277 · NVD
Monitor software like this
Free during beta