Argo Workflows 4.1.0-4.1.3 Auth Bypass in ListArchivedWorkflows via Neg NS selector
CVE-2026-93991 Published on September 19, 2026

Argo Workflows 4.1.0 through 4.1.3 Cross-Namespace Disclosure via Negated Selector
Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. Attackers with namespace-scoped list permissions can use a negated namespace field selector to retrieve archived workflows from all other namespaces, exposing spec arguments, parameter values, and annotations.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-93991 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE

Weakness Type

What is an Insecure Direct Object Reference / IDOR Vulnerability?

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

CVE-2026-93991 has been classified to as an Insecure Direct Object Reference / IDOR vulnerability or weakness.


Products Associated with CVE-2026-93991

Want to know whenever a new CVE is published for Argoproj Argo Workflows? stack.watch will email you.

 

Affected Versions

argoproj argo-workflows: