CVE-2026-93991 UNKNOWN

CVE-2026-93991

Published: 2026-09-19

Description

Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. Attackers with namespace-scoped list permissions can use a negated namespace field selector to retrieve archived workflows from all other namespaces, exposing spec arguments, parameter values, and annotations.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…