← Terug naar overzicht

CVE-2026-82277 affects Argo Rollouts dashboard through version 1.10.0, which binds to all network interfaces and exposes mutating Rollout operations without any authentication, authorization, or CSRF protection. Attackers on the same network can invoke critical operations including PromoteRollout, AbortRollout, RestartRollout, SetRolloutImage, UndoRollout, and RetryRollout. These operations are accessible across all namespaces reachable by the operator's kubeconfig, significantly expanding the attack surface. The vulnerability is essentially an unauthenticated remote access flaw in a Kubernetes deployment management tool. No special privileges are required for an attacker to exploit this issue, only network adjacency. The flaw poses a high risk to Kubernetes environments using Argo Rollouts for progressive delivery and canary deployments.

Affected products

  • Argo Rollouts dashboard

Related CVE's

  • CVE-2026-82277

Categories

  • Cloud & Virtualization
  • Identity & Access
  • Web Technologies