← Back to CVE List
CVE-2026-77459NVD
Vulnerability Summary
Impact Argo CD checks an Application's AppProject before it creates resources during a sync. That check covers destination namespaces and servers, cluster-scoped resource allow and deny lists, and namespaced resource allow and deny lists, including resource names. PreDelete and PostDelete hooks skip it. When the Application is deleted, Argo CD creates those hooks with the application-controller's credentials on the destination cluster. All versions from v2.10.0 onward are affected, including every currently supported release. v2.9.22 and earlier are not. PostDelete hooks were introduced in dcc17f70bf (2023-12-18, #16595) and first released in v2.10.0. That creation path has never applied the project check. PreDelete hooks, added in 3bf3d8a212 (2025-12-05, #22288) and first released in v3.3.0, use the same path. v3.2.12 and earlier do not have PreDelete hooks. PreSync, Sync, PostSync, and SyncFail hooks still go through the project check. A user who can push to the Git repository an Application syncs from can commit a hook whose namespace, group, kind, or name the AppProject would refuse on sync. The controller adds the delete finalizer when it sees the hook, and the Application stays Synced until someone deletes it. Deleting the Application creates the hook. What that can reach is bounded by the application-controller's access to the destination cluster. In a typical install that access is broad, so a tenant can create a cluster-scoped object such as a `ClusterRoleBinding`, or an object in a namespace the project does not allow. A hook with no deletion policy is removed after it succeeds. A deletion policy that does not remove the hook on success leaves the object in the cluster. A hook such as a Job can create further objects that Argo CD does not clean up. Patches A patch for this vulnerability has been released in the following Argo CD versions: v3.6.0-rc2 v3.5.4 v3.4.10 v3.3.15 The fix applies the same AppProject destination and resource checks used on sync before creating a PreDelete or PostDelete hook. Argo CD 2.x and 3.0 through 3.2 are out of support and will not receive a patch. Upgrade to a patched 3.3 or newer release. Workarounds There is no configuration setting that applies the project check to delete hooks while those hooks stay in use. Do not grant untrusted users write access to Git repositories that back Applications in restrictive AppProjects. Limit who can delete Applications. Deletion is what runs PreDelete and PostDelete hooks. Tighten the application-controller's Kubernetes access so a hook cannot reach sensitive namespaces or APIs. Credits The Argo CD team would like to thank @RealFakeAccount, @AdamKorcz, @0xshylines, @thevilledev, @HenriWilliams, @cherez0ff, @ARSB1, and @zwindler for responsibly disclosing this issue according to our security reporting guidelines. References PostDelete introducing commit: dcc17f70bf7db973fe480b8b613189b2c5ac4b4b (#16595), first released in v2.10.0 PreDelete introducing commit: 3bf3d8a2124e772ac651f3fd42375c4e9b8008af (#22288), first released in v3.3.0 AppProject specification Resource hooks For more information Open an issue in the Argo CD issue tracker or discussions * Join us on Slack in channel #argo-cd
CVSS v3.1 Base Metrics — Score 9.9
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- github.com/argoproj/argo-cd/v2 >= 2.10.0
- github.com/argoproj/argo-cd/v3 >= 3.0.0, < 3.3.15 || >= 3.4.0, < 3.4.10 || >= 3.5.0, < 3.5.4 || = 3.6.0-rc1
- github.com/argoproj/argo-cd/v3 3.3.15, 3.4.10, 3.5.4, 3.6.0-rc2