Bug 2525669 (CVE-2026-82277)

Summary: CVE-2026-82277 argo-rollouts: argo-rollouts: Argo Rollouts Dashboard Unauthenticated Mutating Operations
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: urgent Docs Contact:
Priority: urgent    
Version: unspecifiedCC: anjoseph, jprabhak, wtam
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A missing-authentication flaw (CWE-306) was found in the Argo Rollouts dashboard. The dashboard binds to all network interfaces (0.0.0.0) and exposes mutating Rollout operations — including PromoteRollout, AbortRollout, RestartRollout, SetRolloutImage, UndoRollout, and RetryRollout — without any authentication, authorization, or CSRF protection. An attacker with network access to the dashboard port can invoke these operations against any Rollout in the namespaces reachable through the operator's kubeconfig, allowing unauthorized promotion, rollback, restart, or image modification of workloads. This can lead to a complete compromise of the integrity and availability of managed application rollouts.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-28 19:41:55 UTC
Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection. Attackers on the same network can invoke PromoteRollout, AbortRollout, RestartRollout, SetRolloutImage, UndoRollout, and RetryRollout operations across all namespaces accessible to the operator's kubeconfig.