CVE-2026-82456: argocd-mcp 0.8.0 Authentication Bypass via Unauthenticated HTTP

Published Aug 29, 2026
·
Updated

argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCDAPITOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the operator's stored token to create applications, request syncs, and modify Argo CD resources.

Affected Software

1 affected component
argocd-mcp=0.8.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    In argocd-mcp 0.8.0, limit the HTTP transport binding so the listener is not exposed on every network interface; bind only to the specific interface(s) needed.

    argocd-mcp HTTP transport bind address / interface = Bind only to required network interfaces (avoid 0.0.0.0 / all interfaces)
  2. Configuration

    In argocd-mcp 0.8.0, ensure MCP sessions over HTTP require caller credentials even when ARGOCD_API_TOKEN is configured; do not allow unauthenticated sessions.

    argocd-mcp MCP session authentication requirement when ARGOCD_API_TOKEN is configured = Require caller credentials (do not accept unauthenticated MCP sessions)
  3. Compensating control

    Restrict network access to the argocd-mcp HTTP listener so that only trusted clients can reach the listener (e.g., firewall/ACL allowlisting of source IPs/ports).

Event History

Aug 29, 2026
CVE Published
via MITRE·01:47 PM
Data Sourced
via MITRE·01:47 PM
DescriptionSeverityWeakness

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203