Skip to content
← LibraryTechnique entry
CI-ARGOCD-TAKEOVERPrivilege Escalation

ArgoCD Misconfigured RBAC

Default admin/admin or over-broad RBAC lets attackers create Applications pointing at attacker manifests — cluster takeover.

§ Where this technique fits

CI-ARGOCD-TAKEOVER is catalogued under the Privilege Escalation tactic of the offensive-security kill-chain. It appears in 1 approved dossier in the registry, typically at step 3 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    Malicious CronJob / DaemonSet
    K-CRONJOB-PERSIST · Persistence
    seen 1×