CVE-2026-93991: Argo Workflows 4.1.0 through 4.1.3 Cross-Namespace Disclosure via Negated Selector

Published Sep 19, 2026
·
Updated

Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. Attackers with namespace-scoped list permissions can use a negated namespace field selector to retrieve archived workflows from all other namespaces, exposing spec arguments, parameter values, and annotations.

Affected Software

1 affected component
Argo Argo Workflows>=4.1.0<=4.1.3

Event History

Sep 19, 2026
CVE Published
via MITRE·10:58 PM
Data Sourced
via MITRE·10:58 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs namespace-scoped permission to list archived workflows. They can then submit a ListArchivedWorkflows request using a metadata.namespace field selector with the NotEquals operator.

2

What information could be exposed?

The issue can disclose archived workflows from other namespaces, including workflow spec arguments, parameter values, and annotations. The described impact is confidentiality exposure; integrity and availability impacts are not identified.

3

Are all deployments affected by default?

Only Argo Workflows 4.1.0 through 4.1.3 are identified as affected. Exploitation additionally depends on a user or service account having namespace-scoped archived-workflow list permissions.

4

How can I determine whether exploitation may have occurred?

Review ListArchivedWorkflows requests from principals with namespace-scoped list permissions for metadata.namespace selectors using the NotEquals operator. Such requests may have returned archived workflows outside the caller's authorized namespace.

5

What remediation is available?

Upgrade to Argo Workflows 4.1.4, which is identified in the provided release reference as the available fixed release. If upgrading is delayed, restrict namespace-scoped principals' ability to list archived workflows where operationally feasible.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203