{"id":"CVE-2026-93991","title":"Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator","summary":"Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. A…","severity":"high","cvss":7.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","cwe":["CWE-639"],"vendor":"argoproj","product":"argo-workflows","affected":["argo-workflows >= 4.1.0 < 4.1.4"],"published":"2026-09-19","updated":"2026-09-21","sourceUpdated":"2026-09-21T21:17:21.010","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93991","references":[{"url":"https://github.com/argoproj/argo-workflows","label":"disclosure@vulncheck.com"},{"url":"https://github.com/argoproj/argo-workflows/commit/a40972386c097ddf816d2e60e13f058bedca53d9","label":"disclosure@vulncheck.com"},{"url":"https://github.com/argoproj/argo-workflows/releases/tag/v4.1.4","label":"disclosure@vulncheck.com"},{"url":"https://github.com/argoproj/argo-workflows/security/advisories/GHSA-q65w-j2vp-47c4","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/argo-workflows-4.1.0-through-4.1.3-cross-namespace-disclosure-via-negated-selector","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-21T16:23:00.522517Z"},"epss":0.00326,"epssPercentile":0.25856,"ingestedAt":"2026-09-19T23:10:34.245Z","slug":"CVE-2026-93991","body":"## Overview\n\nArgo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. Attackers with namespace-scoped list permissions can use a negated namespace field selector to retrieve archived workflows from all other namespaces, exposing spec arguments, parameter values, and annotations.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":42.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}