All verified exploits

CVE-2026-28229 Argo Workflows Unauthorized Template Access

Deterministic high Argo Workflows Added cve-verified-cve-2026-28229

Detects Argo Workflows instances before 3.7.11 or 4.0.2 where the workflow template endpoints bypass authorization checks. Any request with a bearer token can retrieve WorkflowTemplates and ClusterWorkflowTemplates, including embedded Secret manifests with database passwords, API keys, and cloud credentials.

Is your app exploitable through CVE-2026-28229?

Scan your domain free