CVE-2026-6388 is a critical vulnerability in ArgoCD Image Updater that permits attackers with ImageUpdater resource creation or modification permissions to circumvent namespace isolation in multi-tenant environments. By exploiting insufficient validation controls, threat actors can trigger unauthorized image updates across tenant boundaries, effectively escalating privileges and compromising application integrity through cross-namespace exploitation. The vulnerability carries a CVSS score of 9.1 (Critical) with a network-based attack vector requiring low complexity and minimal user interaction. The attack requires low privileges but impacts the system in ways that cross security boundaries, resulting in moderate confidentiality impact, high integrity impact, and partial availability degradation. This severity profile indicates significant risk to multi-tenant Kubernetes deployments relying on ArgoCD Image Updater. Exploitation status remains limited, with no confirmed active exploitation in the wild and no public exploit code availability. The vulnerability does not currently appear on the KEV catalog, and community attention remains relatively low. However, organizations should prioritize patching given the critical rating and the relative ease of exploitation for malicious insiders or compromised accounts with namespace-level permissions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Red Hat | Red Hat OpenShift GitOps | All Versions ImpactedCNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.