CVE-2026-82456
argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGO
CVSS
10.0
Crítico
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 29 ago 2026 · Última mod.: 29 ago 2026 · CWE-1327
Sin historial EPSS suficiente todavía.
argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the operator's stored token to create applications, request syncs, and modify Argo CD resources.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-167134.3 MED16.4%
——5IBM Documentation Offline 1.0.0 through 1.4.1 IBM Documentation could allow a remote attacker to obtain sensitive information due to a security misconfiguration where the documentation server binds to an unrestricted IP address.12dCVE-2026-165039.1 CRÍ24.4%
——7Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to "postgres". Because Docker installs its own iptables rules, this exposure bypasses a standard host UFW configuration.26dCVE-2026-478738.0 ALT9.3%
——3The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0.0.0.0) rather than restricting them to loopback.
Affected Spring Products and Versions:
Spring Tools for Eclipse: 5.2.0 and earlier29d