Back Redpacketsecurity CVE Alert: CVE-2026-93991 – argoproj – argo
Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. Attackers with namespace-scoped list permissions can use a negated namespace field selector to retrieve archived workflows from all other namespaces, exposing spec arguments, parameter values, and annotations.
High-priority confidentiality risk requiring prompt remediation; KEV, SSVC exploitation status, EPSS and PoC indicators were not supplied, so active exploitation cannot be confirmed.
A low-privilege account could access workflow data beyond its authorised namespace, potentially exposing credentials, tokens, deployment parameters, image references and sensitive operational metadata embedded in workflow records. This is primarily an intelligence and secrets-disclosure issue, with possible follow-on compromise of cloud, CI/CD or production environments if exposed values remain valid.
### Most likely attack path
The attack is network-reachable, requires low privileges, has low complexity and needs no user interaction. An attacker with legitimate namespace-scoped listing access would manipulate a namespace selector to obtain records outside that boundary; the changed scope indicates impact can cross administrative or tenant boundaries, although integrity and availability are not directly affected.
### Who is most exposed
Organisations running shared, multi-tenant Argo Workflows installations, particularly where users, teams or customers have separate namespaces, face the greatest risk. Internet-accessible or broadly reachable workflow APIs and environments storing secrets or production deployment parameters are especially sensitive.
Review API audit logs for unusual negated namespace selectors.
Identify list requests followed by access across multiple namespaces.
Alert on principals enumerating archived workflows outside their normal scope.
workflow arguments, annotations and parameters for exposed secrets or tokens.
### Mitigation and prioritisation
Upgrade to the vendor-fixed release or later; treat patching as high priority.
Until patched, restrict API exposure and remove unnecessary namespace-list permissions.
Rotate credentials, tokens and deployment secrets found in archived workflows.
Add temporary authorisation or proxy rules blocking negated namespace selectors.
Validate KEV, SSVC, EPSS and PoC status before final queue placement, and test the change in a representative multi-namespace environment.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
