Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/haerin-l/poc_cve-2026-42880
Vulnerability AnalysisExploitationPenetration TestingCloud SecurityMisconfigurationLearning & EducationLabs & Practice
GitHubhaerin-l/poc_cve-2026-42880

POC_CVE-2026-42880

Reproduces CVE-2026-42880, a critical ArgoCD vulnerability exposing Kubernetes Secrets via ServerSideDiff. Includes automated lab setup, trigger scripts, and a Nuclei detection template for security testing.

View Repository
23 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-42880 — ArgoCD Secret Exposure via ServerSideDiff

A lab environment for reproducing and detecting CVE-2026-42880, a critical vulnerability in Argo CD where the ServerSideDiff gRPC handler exposes Kubernetes Secret data to read-only users.


Vulnerability Overview

FieldDetails
CVE IDCVE-2026-42880
GHSAGHSA-3v3m-wc6v-x4x3
CVSS9.6 (Critical) — AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Affected versionsArgoCD 3.2.0–3.2.10, 3.3.0–3.3.8
Patched versions3.2.11, 3.3.9+
CWECWE-200, CWE-212

Root Cause

serverSideDiff() in ArgoCD's gRPC handler calls the Kubernetes SSA dry-run and returns predictedLive without calling hideSecretData(), exposing base64-encoded Secret values in the response.

root@kitploit:~
Vulnerable path (v3.2.0):
argocd app diff --server-side-diff
  → gRPC ServerSideDiff handler
    → Kubernetes SSA dry-run (merges ALL field managers)
      ← predictedLive returned (includes external-controller's data)
        ❌ hideSecretData() NOT called → real Secret values exposed

Patched path (v3.2.11):
  ...same SSA dry-run...
    ✅ HideSecretData() called → values replaced with ++++

Attack Prerequisites

All three conditions must be met simultaneously:

#ConditionDetails
1Vulnerable ArgoCD version3.2.0–3.2.10 or 3.3.0–3.3.8
2Application annotationargocd.argoproj.io/compare-options: ServerSideDiff=true,IncludeMutationWebhook=true
3External field manager on Secret dataSecret data fields owned by a non-ArgoCD manager (e.g., External Secrets Operator, Helm, kubectl)

Only role:readonly is required — no write permissions needed.


Lab Architecture

root@kitploit:~
Host Machine
├── localhost:30080 ──→ Kind Cluster: cve-vuln   (ArgoCD v3.2.0  ⚠ VULNERABLE)
│                         └── ns: production
│                              ├── Secret: db-credentials
│                              │    metadata → argocd-controller (synced from Git)
│                              │    data.*  → external-controller ⚠ (injected separately)
│                              └── Secret: api-credentials (same setup)
│
├── localhost:30081 ──→ Kind Cluster: cve-patched (ArgoCD v3.2.11 ✓ PATCHED)
│                         └── (identical config — only ArgoCD version differs)
│
└── localhost:3010  ──→ Docker Container: cve-lab-gitea
                          └── repo: gitadmin/manifests.git
                               └── secret.yaml (no data field — CVE prerequisite)

Why the field manager split matters

root@kitploit:~
db-credentials Secret (namespace: production)
┌──────────────────────────────────────────────────────────────┐
│  metadata.*  → argocd-controller   (ArgoCD syncs from Git)   │
│  data.*      → external-controller (injected by setup script)│
└──────────────────────────────────────────────────────────────┘

SSA dry-run: Kubernetes merges both managers' fields into predictedLive
  → ArgoCD does NOT own data → data is not masked by ArgoCD
  → v3.2.0 returns predictedLive without hideSecretData() → EXPOSED

Prerequisites

ToolInstall
kindbrew install kind
kubectlbrew install kubectl
Docker Desktopdocker.com
argocd CLIbrew install argocd
nucleibrew install nuclei
curl, jq, gitpre-installed on macOS or brew install jq

Resource requirements: 8GB+ free RAM, 15GB+ free disk, ports 30080 / 30081 / 3010 available.


How to Run

Step 1 — Set up vulnerable environment (ArgoCD v3.2.0)

root@kitploit:~
bash scripts/01-setup-vuln.sh
# or: make setup-vuln

Takes ~10 minutes. When done:

root@kitploit:~
══════════════════════════════════════════════════════
 Vulnerable ArgoCD lab ready!
══════════════════════════════════════════════════════
 ArgoCD UI   : http://localhost:30080
 Admin pass  : <auto-generated>
 Viewer pass : viewerpass123
 Token file  : .vuln-viewer-token
══════════════════════════════════════════════════════

Step 2 — Set up patched environment for comparison (optional)

root@kitploit:~
bash scripts/02-setup-patched.sh
# or: make setup-patched

Step 3 — Trigger the CVE

root@kitploit:~
bash scripts/03-trigger-cve.sh
# or: make trigger

Expected output — vulnerable (v3.2.0):

root@kitploit:~
===== /Secret production/db-credentials ======
<   db_password: ++++++++                          ← masked live state
---
>   db_password: U3VwM3JTM2NyM3REQiFQYXNzIzIwMjY=  ← EXPOSED predictedLive!

[EXPOSED] decoded: Sup3rS3cr3tDB!Pass#2026
⚠  RESULT: SECRET DATA EXPOSED — VULNERABLE

Expected output — patched (v3.2.11):

root@kitploit:~
>   db_password: ++++++++   ← masked
✓  RESULT: no unmasked data in predictedLive — PATCHED

Step 4 — Nuclei detection

root@kitploit:~
# Vulnerable cluster → should produce a [critical] finding
nuclei -t nuclei/CVE-2026-42880.yaml \
  -u http://localhost:30080 \
  -var username=viewer \
  -var password=viewerpass123

# Patched cluster → should produce no findings
nuclei -t nuclei/CVE-2026-42880.yaml \
  -u http://localhost:30081 \
  -var username=viewer \
  -var password=viewerpass123

Step 5 — Teardown

root@kitploit:~
bash scripts/99-teardown.sh
# or: make teardown

Directory Structure

root@kitploit:~
argocd-cve-2026-42880-lab2/
├── README.md
├── LAB_SETUP_GUIDE.md              # Lab setup guide + troubleshooting (English)
├── VULNERABILITY_ANALYSIS.md       # Code-level vulnerability analysis (English)
├── Nuclei_Template_Report.md       # Nuclei template design and test results (English)
├── Makefile
│
├── REPORT/                         # Korean reports
│   ├── LAB_REPORT_KR.md
│   ├── Nuclei_Template_Report_KR.md
│   └── Vulnerability_Analysis_KR.md
│
├── kind/
│   ├── cluster-vuln.yaml           # Kind cluster: cve-vuln    (port 30080)
│   └── cluster-patched.yaml        # Kind cluster: cve-patched (port 30081)
│
├── git-manifests/
│   └── secret.yaml                 # Secret without data field (CVE prerequisite)
│
├── manifests/
│   ├── application.yaml            # ArgoCD Application with vulnerable annotation
│   ├── argocd-cm-patch.yaml        # ConfigMap: TLS off, viewer account, ServerSideDiff
│   ├── argocd-rbac-patch.yaml      # RBAC: viewer → role:readonly
│   ├── argocd-nodeport.yaml        # NodePort 30080 (vuln cluster)
│   └── argocd-nodeport-patched.yaml# NodePort 30081 (patched cluster)
│
├── nuclei/
│   └── CVE-2026-42880.yaml         # Nuclei detection template
│
└── scripts/
    ├── 01-setup-vuln.sh            # Full automated setup: vulnerable env
    ├── 02-setup-patched.sh         # Full automated setup: patched env
    ├── 03-trigger-cve.sh           # Trigger CVE + compare both clusters
    └── 99-teardown.sh              # Remove all lab resources

Nuclei Template Detection Logic

The template uses a 4-step HTTP chain to verify all CVE prerequisites without triggering actual Secret extraction:

root@kitploit:~
Step 1  GET /api/version
        → extract argocd_version (no auth required)

Step 2  POST /api/v1/session
        → authenticate as viewer (role:readonly), extract token

Step 3  GET /api/v1/applications
        → find app with ServerSideDiff=true,IncludeMutationWebhook=true

Step 4  GET /api/v1/applications/{app}/managed-resources
        → verify: version in range + Secret present + f:data owned by external manager
        → FINDING reported only if all 5 matchers pass (AND condition)

References

  • NVD — CVE-2026-42880
  • GHSA-3v3m-wc6v-x4x3
  • Patch PR #27598
  • ArgoCD Server-Side Diff docs
  • Kubernetes Server-Side Apply

Warning: All credentials in this lab are fake test data for security research purposes only. Never use in production.

Download Tool