Detects Argo Workflows instances before 3.7.11 or 4.0.2 where the workflow template endpoints bypass authorization checks. Any request with a bearer token can retrieve WorkflowTemplates and ClusterWorkflowTemplates, including embedded Secret manifests with database passwords, API keys, and cloud credentials.
Is your app exploitable through CVE-2026-28229?
Scan your domain free