CVE-2026-82456

argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the operator's stored token to create applications, request syncs, and modify Argo CD resources.

  • Published Aug 29, 2026
  • CVSS 10.0 critical
  • 1.7% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-82456 at the National Vulnerability Database