Junglewise Threat Intelligence

CVE-2026-6388: ArgoCD Image Updater cross-namespace privilege escalation

CVE-2026-6388 · Severity: critical · CVSS 9.1 · Published 2026-04-15

Vendors: Red Hat, Argo Project.

Executive brief

A security flaw in ArgoCD Image Updater allows users with limited permissions to bypass security boundaries in multi-tenant environments. This tool is used to automatically update container images in Kubernetes clusters. An attacker could exploit this to force unauthorized software updates on applications belonging to other teams or departments, potentially compromising the integrity of critical business services.

Technical details

A cross-namespace privilege escalation vulnerability exists in ArgoCD Image Updater due to insufficient validation of namespace boundaries (CWE-1220). In multi-tenant environments where the controller operates with broad cluster-level permissions, an attacker with local network access and the ability to create or modify ImageUpdater resources can bypass isolation. By exploiting this lack of granularity in access control, the attacker can trigger unauthorized image updates on applications managed by other tenants. This vulnerability affects Red Hat OpenShift GitOps versions prior to v1.19.2. Remediation involves upgrading to a patched version or restricting controller permissions to specific designated namespaces.

Affected products

  • Argo Project ArgoCD Image Updater
  • Red Hat Red Hat OpenShift GitOps < 1.19.2

Timeline

  • 2026-04-15: disclosed
  • 2026-04-15: advisory

References