Skip to content
Critical CVEs Disclosed for Kaneo and Argo Workflows

Critical CVEs Disclosed for Kaneo and Argo Workflows

First seen 23 Sep 2026, 00:57 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 23, 2026 at 01:59 UTC
  • CVE-2026-63104 allows unauthorized task modifications in Kaneo.
  • CVE-2026-93991 exposes archived workflows across namespaces in Argo Workflows.
  • Patches for both vulnerabilities are available; immediate action is recommended.

Two high-priority vulnerabilities have been disclosed affecting Kaneo and Argo Workflows. CVE-2026-63104 in Kaneo allows low-privileged users to delete or modify tasks via a flawed bulk task endpoint, impacting task integrity. CVE-2026-93991 in Argo Workflows permits attackers to access archived workflows across namespaces, risking exposure of sensitive operational metadata. Both vulnerabilities require urgent remediation, with Kaneo's patch released on September 22, 2026, and Argo's on September 19, 2026. No active exploitation has been confirmed for either CVE, but proof-of-concept indicators exist for Kaneo. Organizations using these platforms should audit permissions and apply patches immediately to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-19
CVE-2026-93991 published
Argo Workflows versions 4.1.0 to 4.1.3 have an authorization bypass vulnerability.
Redpacketsecurity
2026-09-22
CVE-2026-63104 published
Kaneo versions 2.3.12 to 2.12.2 contain a missing authorization vulnerability.
Redpacketsecurity
Recent
Patches released for both CVEs
Kaneo and Argo Workflows have issued patches to address the vulnerabilities; organizations are urged to apply them immediately.
Redpacketsecurity

More articles in this cluster (3)

Following this threat?

Track CVE-2026-63104 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed