argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the operator's stored token to create applications, request syncs, and modify Argo CD resources.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
argocd-mcp 0.8.0 contains a critical authentication bypass vulnerability where the HTTP transport binds to all network interfaces and accepts MCP (Model Context Protocol) sessions without credential validation when ARGOCD_API_TOKEN is present in the environment. This allows any attacker with network access to the listener to leverage the operator's stored token to perform unauthorized actions on Argo CD resources—including creating applications, triggering syncs, and modifying critical GitOps infrastructure. Organizations using Argo CD for continuous deployment are directly impacted, particularly those with argocd-mcp exposed on accessible networks or in multi-tenant environments where network segmentation may be incomplete.
While this CVE currently maps to zero Casky skills due to its novelty, practitioners should focus detection efforts on MITRE ATT&CK techniques that would precede and follow exploitation: T1046 (Network Service Discovery) as attackers probe for exposed argocd-mcp listeners, T1589 (Gather Victim Identity Information) when reconnaissance targets API token locations, and T1550 (Use Alternate Authentication Material) when attackers leverage the stored ARGOCD_API_TOKEN to authenticate without credentials. Post-exploitation, practitioners would detect T1578 (Modify Cloud Compute Infrastructure) and T1565 (Data Manipulation) as attackers create malicious applications or alter deployment configurations. Security teams should implement network monitoring for unexpected MCP protocol traffic, audit logs for resource modifications originating from unexpected sources, and employ Casky's extended reasoning capabilities to correlate unauthenticated connection attempts with subsequent Argo CD API activity—identifying the attack chain from discovery through command execution.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-82456. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation