Back to blog
Cybersecurity

ArgoCD RCE: How Unauthenticated gRPC Enables Full Kubernetes Cluster Takeover

Active ArgoCD RCE: unauthenticated gRPC enables full Kubernetes cluster takeover. Real mechanism, detection commands, and step-by-step remediation for IT teams.

Blurtek
8 min read77 palabras
01

The ArgoCD Unauthenticated gRPC Flaw: Real Mechanism and Impact

An active vulnerability in ArgoCD enables remote code execution and full Kubernetes cluster takeover through unauthenticated gRPC calls to the API server. The mechanism is precise: ArgoCD implements authentication as HTTP middleware but not as a native gRPC interceptor, leaving a side door open for direct HTTP/2 clients. Versions prior to branches 2.8.6 and 2.9.3 have the documented flaw. If your instance exposes port 8080 to the internet without NetworkPolicy or VPN, you are exposed right now.

02

How to Detect and Remediate Exposed ArgoCD Instances

Do you have ArgoCD in production and are unsure about your exposure? We audit Kubernetes infrastructure with real gRPC port analysis and NetworkPolicy reviews — concrete findings, no fear-selling.

Solicitar diagnóstico