{"id":"CVE-2026-82456","title":"argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured","summary":"argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface…","severity":"critical","cvss":10,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-1327"],"published":"2026-08-29","updated":"2026-08-29","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-82456","references":[{"url":"https://github.com/argoproj-labs/mcp-for-argocd","label":"disclosure@vulncheck.com"},{"url":"https://github.com/argoproj-labs/mcp-for-argocd/security/advisories/GHSA-rp45-5x3v-48mr","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/argocd-mcp-0.8.0-authentication-bypass-via-unauthenticated-http","label":"disclosure@vulncheck.com"}],"tags":["nvd","exploit-available"],"ingestedAt":"2026-08-30T07:49:08.726Z","epss":0.01391,"epssPercentile":0.70707,"exploits":{"nuclei":["CVE-2026-82456"],"checkedAt":"2026-09-21T15:30:52.792Z"},"exploitAvailable":true,"slug":"CVE-2026-82456","body":"## Overview\n\nargocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the operator's stored token to create applications, request syncs, and modify Argo CD resources.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":67,"depthScoreParts":{"impact":55,"likelihood":0.3,"exploitation":12,"ransomware":0},"changes":[{"seq":207760,"id":"CVE-2026-82456","ts":1789838342797,"field":"exploit_available","old":"false","new":"true"}]}