CVE-2026-32828 is a Server-Side Request Forgery (SSRF) vulnerability affecting Akuity Kargo versions 1.4.0 through 1.9.4, specifically within its http and http-download promotion steps. An authenticated attacker with high privileges can exploit this to access link-local addresses, including cloud instance metadata endpoints, enabling the exfiltration of sensitive data such as IAM credentials. The vulnerability provides full control over request headers, rendering typical cloud provider SSRF mitigations ineffective. Rated as MEDIUM severity (CVSS 4.9), it requires high privileges for exploitation but has low attack complexity. There is currently no evidence of active exploitation, no public exploit code available, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.4.0, < 1.6.4CPE matchmatch criteria | cpe:2.3:a:akuity:kargo:*:*:*:*:*:kubernetes:*:* | ||
>= 1.7.0, < 1.7.9CPE matchmatch criteria | cpe:2.3:a:akuity:kargo:*:*:*:*:*:kubernetes:*:* | ||
>= 1.8.0, < 1.8.12CPE matchmatch criteria | cpe:2.3:a:akuity:kargo:*:*:*:*:*:kubernetes:*:* | ||
>= 1.9.0, < 1.9.5CPE matchmatch criteria | cpe:2.3:a:akuity:kargo:*:*:*:*:*:kubernetes:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.