Critical Vulnerability in argocd-mcp 0.8.0 Allows Unauthenticated Access
A critical vulnerability (CVE-2026-82456) with a CVSS score of 10 has been discovered in argocd-mcp 0.8.0. The vulnerability allows unauthenticated attackers to invoke the full tool surface using the operator's stored token, potentially leading to the creation of applications, request syncs, and modification of Argo CD resources. Immediate action is required to mitigate this vulnerability.