Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-82456: Argo CD MCP 0.8.0 lets anyone on network control system
CVE-2026-82456 · published 5 days ago
Summary
Version 0.8.0 of Argo CD’s management component listens on all network addresses and, when a security token is set, does not verify who is connecting. Anyone who can reach the server can use that token to create or change applications and deployment settings. To protect your environment, limit network access to the server, remove or protect the token, and upgrade to a version that restricts access.
What to do
- Update argoproj-labs argocd-mcp to version 0.9.0 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| argoproj-labs | argocd-mcp | < 0.9.0 |
Original advisory text
argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the l...
argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the operator's stored token to create applications, request syncs, and modify Argo CD resources.
References
Severity
10.0
Critical
CVSS 3.1: 10.0 (MITRE)
Exploitation
EPSS <1%
Type
CWE-1327Binding to an Unrestricted IP Address
Timeline
Published29 Aug 2026
Updated2 Sep 2026
First seen29 Aug 2026
Monitor software like this
Free during beta