CVE-2026-82456CWE-1327

CVE-2026-82456

Critical · published August 29, 2026

CVSS v3.1
10.0
EPSS
0%
Percentile
30.3
In the wild
Unconfirmed
What it is

argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the operator's stored token to create applications, request syncs, and modify Argo CD resources.

The record
Technical detail
CVSS v3.1
10.0 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS v4.0
10.0 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
EPSS
0.00372 · 30.3th percentile
Weakness
CWE-1327 · Binding to an Unrestricted IP Address
Published
2026-08-29T18:16Z
References (4)
EPSS history
Timeline
  • 30 AUG 16:19Z
    EPSS moved — → 0%
    epss
  • 29 AUG 13:47Z
    argocd-mcp 0.8.0 Authentication Bypass via Unauthenticated HTTP
    cvelistv5