CRITICAL 10 CVE-2026-82456 Published 29 Aug 2026

Argo CD MCP Unauthenticated Access

Worried this affects one of your servers?

argocd-mcp 0.8.0 binds its HTTP transport to every network interface.

Attackers can reach the listener and invoke the full tool surface using the operator's stored token.

  • Affected versions: 0.8.0
  • Impact: Unauthenticated access to Argo CD resources

Reference: CVE-2026-82456 on NVD

← Back to Security News