Bug 2525669 (CVE-2026-82277)
| Summary: | CVE-2026-82277 argo-rollouts: argo-rollouts: Argo Rollouts Dashboard Unauthenticated Mutating Operations | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | urgent | Docs Contact: | |
| Priority: | urgent | ||
| Version: | unspecified | CC: | anjoseph, jprabhak, wtam |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A missing-authentication flaw (CWE-306) was found in the Argo Rollouts dashboard. The dashboard binds to all network interfaces (0.0.0.0) and exposes mutating Rollout operations — including PromoteRollout, AbortRollout, RestartRollout, SetRolloutImage, UndoRollout, and RetryRollout — without any authentication, authorization, or CSRF protection. An attacker with network access to the dashboard port can invoke these operations against any Rollout in the namespaces reachable through the operator's kubeconfig, allowing unauthorized promotion, rollback, restart, or image modification of workloads. This can lead to a complete compromise of the integrity and availability of managed application rollouts.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-08-28 19:41:55 UTC
|