CVE-2026-43824: Critical severity Argo Argo CD vulnerability
Published May 2, 2026
·Updated
In Argo CD 3.2.0 before 3.2.11 and 3.3.0 before 3.3.9, ServerSideDiff allows reading cleartext Kubernetes Secret data.
Affected Software
1 affected component
Argo Argo CD>3.2.0<=3.2.10, >3.3.0<=3.3.8
Event History
May 2, 2026
CVE Published
via MITRE·01:20 AM
Data Sourced
via MITRE·01:20 AM
DescriptionSeverityWeakness
Data Sourced
via Red Hat·02:01 AM
DescriptionSeverityAffected Software
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-43824?
CVE-2026-43824 has been rated as a critical vulnerability due to its potential to expose sensitive Kubernetes Secret data.
2
How do I fix CVE-2026-43824?
To fix CVE-2026-43824, upgrade Argo CD to versions 3.2.11 or 3.3.9 and later.
3
What systems are affected by CVE-2026-43824?
CVE-2026-43824 affects Argo CD versions 3.2.0 to 3.2.11 and 3.3.0 to 3.3.9.
4
What is the impact of CVE-2026-43824 on my Kubernetes secrets?
CVE-2026-43824 allows unauthorized users to read Kubernetes Secret data in cleartext, compromising sensitive information.
5
When was CVE-2026-43824 disclosed?
CVE-2026-43824 was disclosed as a vulnerability affecting specific versions of Argo CD before the applicable patches were released.