CVE-2026-93991
Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. Attackers with namespace-scoped list permissions can use a negated namespace field selector to retrieve archived workflows from all other namespaces, exposing spec arguments, parameter values, and annotations.
- Published Sep 19, 2026
- CVSS 8.3 high
- 0.4% chance of exploitation in the next 30 days (EPSS)
- A fix is available