{"dataType":"CVE_RECORD","cveMetadata":{"cveId":"CVE-2026-43824","assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","state":"PUBLISHED","assignerShortName":"mitre","dateReserved":"2026-05-02T01:20:32.951Z","datePublished":"2026-05-02T01:20:33.348Z","dateUpdated":"2026-07-15T00:55:34.280Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Argo CD","vendor":"argoproj","versions":[{"lessThan":"3.2.11","status":"affected","version":"3.2.0","versionType":"semver"},{"lessThan":"3.3.9","status":"affected","version":"3.3.0","versionType":"semver"}]}],"descriptions":[{"lang":"en","value":"In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.7,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-212","description":"CWE-212 Improper Removal of Sensitive Information Before Storage or Transfer","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre","dateUpdated":"2026-05-02T01:42:18.517Z"},"references":[{"url":"https://github.com/argoproj/argo-cd/security/advisories/GHSA-3v3m-wc6v-x4x3"}],"x_generator":{"engine":"CVE-Request-form 0.0.1"},"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2.0","versionEndExcluding":"3.2.11"},{"vulnerable":true,"criteria":"cpe:2.3:a:argoproj:argo_cd:*:*:*:*:*:*:*:*","versionStartIncluding":"3.3.0","versionEndExcluding":"3.3.9"}]}]}]},"adp":[{"references":[{"url":"https://github.com/argoproj/argo-cd/security/advisories/GHSA-3v3m-wc6v-x4x3","tags":["exploit"]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-05-04T13:32:13.742342Z","id":"CVE-2026-43824","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-05-04T13:32:17.895Z"}},{"affected":[{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openshift_data_foundation:4"],"defaultStatus":"unaffected","packageName":"odf4/odf-multicluster-rhel9-operator","product":"Red Hat Openshift Data Foundation 4","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openshift_gitops:1"],"defaultStatus":"unaffected","packageName":"openshift-gitops-1/argocd-agent-rhel8","product":"Red Hat OpenShift GitOps","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openshift_gitops:1"],"defaultStatus":"unaffected","packageName":"openshift-gitops-1/argocd-agent-rhel9","product":"Red Hat OpenShift GitOps","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openshift_gitops:1"],"defaultStatus":"unaffected","packageName":"openshift-gitops-1/argocd-image-updater-rhel8","product":"Red Hat OpenShift GitOps","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openshift_gitops:1"],"defaultStatus":"unaffected","packageName":"openshift-gitops-1/argocd-image-updater-rhel9","product":"Red Hat OpenShift GitOps","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openshift_gitops:1"],"defaultStatus":"unaffected","packageName":"openshift-gitops-1/argocd-rhel8","product":"Red Hat OpenShift GitOps","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openshift_gitops:1"],"defaultStatus":"unaffected","packageName":"openshift-gitops-1/argocd-rhel9","product":"Red Hat OpenShift GitOps","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openshift_gitops:1"],"defaultStatus":"unaffected","packageName":"openshift-gitops-1/gitops-rhel8","product":"Red Hat OpenShift GitOps","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openshift_gitops:1"],"defaultStatus":"unaffected","packageName":"openshift-gitops-1/gitops-rhel8-operator","product":"Red Hat OpenShift GitOps","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openshift_gitops:1"],"defaultStatus":"unaffected","packageName":"openshift-gitops-1/gitops-rhel9","product":"Red Hat OpenShift GitOps","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openshift_gitops:1"],"defaultStatus":"affected","packageName":"openshift-gitops-1/gitops-rhel9-operator","product":"Red Hat OpenShift GitOps","vendor":"Red Hat"}],"datePublic":"2026-05-02T01:20:33.348Z","descriptions":[{"lang":"en","value":"A flaw was found in Argo CD. The ServerSideDiff feature allows for the reading of cleartext Kubernetes Secret data. This vulnerability could lead to information disclosure, potentially exposing sensitive configuration details within the Kubernetes environment."}],"metrics":[{"other":{"content":{"namespace":"https://access.redhat.com/security/updates/classification/","value":"Important"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":9.6,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","version":"3.1"},"format":"CVSS"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-312","description":"Cleartext Storage of Sensitive Information","lang":"en","type":"CWE"}]}],"references":[{"tags":["vdb-entry","x_refsource_REDHAT"],"url":"https://access.redhat.com/security/cve/CVE-2026-43824"},{"name":"RHBZ#2464613","tags":["issue-tracking","x_refsource_REDHAT"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2464613"},{"tags":["x_sadp-csaf-vex"],"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-43824.json"}],"timeline":[{"lang":"en","time":"2026-05-02T02:00:52.099Z","value":"Reported to Red Hat."},{"lang":"en","time":"2026-05-02T01:20:33.348Z","value":"Made public."}],"title":"github.com/argoproj/argo-cd/: Argo CD: Information disclosure via ServerSideDiff allows reading Kubernetes Secret data","workarounds":[{"lang":"en","value":"Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability."}],"x_adpType":"supplier","x_generator":{"engine":"sadp-cli 1.0.0"},"providerMetadata":{"orgId":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","shortName":"redhat-SADP","dateUpdated":"2026-07-15T00:55:34.280Z"}}]},"dataVersion":"5.2"}