VendorsAkuitykargoany version
Vulnerabilities

Akuity Kargo any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2026-27112
Kargo has an Authorization Bypass Vulnerability in Batch Resource Creation API Endpoints
Published 2026-02-20 · Analyzed
9.9EPSS 0.008
CVE-2026-24748
Kargo's `GetConfig()` and `RefreshResource()` API endpoints allow unauthenticated access
Published 2026-01-27 · Analyzed
7.2EPSS 0.004
CVE-2026-27111
Kargo has Missing Authorization Vulnerabilities in Approval & Promotion REST API Endpoints
Published 2026-02-20 · Analyzed
5.3EPSS 0.003
CVE-2026-32828
Kargo: SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration
Published 2026-03-20 · Analyzed
5.1EPSS 0.004