CVE-2026-82456

argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the operator's stored token to create applications, request syncs, and modify Argo CD resources.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-29 14:16

Updated : 2026-09-02 19:18


NVD link : CVE-2026-82456

Mitre link : CVE-2026-82456

CVE.ORG link : CVE-2026-82456


JSON object : View

Products Affected

No product.

CWE
CWE-1327

Binding to an Unrestricted IP Address