Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-6388

Опубликовано: 15 апр. 2026
Источник: redhat
CVSS3: 9.1
EPSS Низкий

Описание

A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker, with permissions to create or modify an ImageUpdater resource in a multi-tenant environment, to bypass namespace boundaries. By exploiting insufficient validation, the attacker can trigger unauthorized image updates on applications managed by other tenants. This leads to cross-namespace privilege escalation, impacting application integrity through unauthorized application updates.

Отчет

Critical: A cross-namespace privilege escalation flaw in Argo CD Image Updater, a component of Red Hat OpenShift GitOps, allows an attacker with permissions to create or modify ImageUpdater resources to trigger unauthorized image updates on applications in other namespaces. This impacts multi-tenant environments where the controller operates with broad cluster-level permissions. Red Hat OpenShift GitOps versions prior to v1.19.2 are affected.

Меры по смягчению последствий

Ensure that AppProject resources are configured to enforce strict tenant isolation within Red Hat OpenShift GitOps environments. Additionally, restrict the permissions of the Argo CD Image Updater controller to operate only within its designated namespaces, and limit the ability of users to create or modify ImageUpdater resources to trusted administrators. This reduces the risk of unauthorized cross-namespace application updates.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift GitOpsopenshift-gitops-1/argocd-image-updater-rhel8Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1220
https://bugzilla.redhat.com/show_bug.cgi?id=2458766argocd-image-updater: ArgoCD Image Updater: Cross-Namespace Privilege Escalation via insufficient namespace validation

EPSS

Процентиль: 23%
0.00313
Низкий

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.1
nvd
4 месяца назад

A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker, with permissions to create or modify an ImageUpdater resource in a multi-tenant environment, to bypass namespace boundaries. By exploiting insufficient validation, the attacker can trigger unauthorized image updates on applications managed by other tenants. This leads to cross-namespace privilege escalation, impacting application integrity through unauthorized application updates.

CVSS3: 9.1
github
4 месяца назад

A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker, with permissions to create or modify an ImageUpdater resource in a multi-tenant environment, to bypass namespace boundaries. By exploiting insufficient validation, the attacker can trigger unauthorized image updates on applications managed by other tenants. This leads to cross-namespace privilege escalation, impacting application integrity through unauthorized application updates.

EPSS

Процентиль: 23%
0.00313
Низкий

9.1 Critical

CVSS3