CVE-2026-93991: Argoproj Argo-Workflows
High severity, CVSS 7.7. EPSS: 0.4% chance of exploitation in the next 30 days.
Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. Attackers with namespace-scoped list permissions can use a negated namespace field selector to retrieve archived workflows from all other namespaces, exposing spec arguments, parameter values, and annotations.
Affected products
- Argoproj Argo-Workflows: from 4.1.0, before 4.1.4 (fixed in 4.1.4)
Published 2026-09-19. Last modified 2026-09-22.