Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6388

34
FAUCET Score

CVE-2026-6388 is a critical vulnerability in ArgoCD Image Updater that permits attackers with ImageUpdater resource creation or modification permissions to circumvent namespace isolation in multi-tenant environments. By exploiting insufficient validation controls, threat actors can trigger unauthorized image updates across tenant boundaries, effectively escalating privileges and compromising application integrity through cross-namespace exploitation. The vulnerability carries a CVSS score of 9.1 (Critical) with a network-based attack vector requiring low complexity and minimal user interaction. The attack requires low privileges but impacts the system in ways that cross security boundaries, resulting in moderate confidentiality impact, high integrity impact, and partial availability degradation. This severity profile indicates significant risk to multi-tenant Kubernetes deployments relying on ArgoCD Image Updater. Exploitation status remains limited, with no confirmed active exploitation in the wild and no public exploit code availability. The vulnerability does not currently appear on the KEV catalog, and community attention remains relatively low. However, organizations should prioritize patching given the critical rating and the relative ease of exploitation for malicious insiders or compromised accounts with namespace-level permissions.

Impacted Technologies

VendorProductVersion(s)CPE
Red HatRed Hat OpenShift GitOps
All Versions ImpactedCNA affecteddefault affected

CVSS Data

CVSS version used by this source: 3.1

9.1CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
3.1
Impact Score
5.3
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.36%
Probability of exploitation in next 30 days
EPSS Percentile
28.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0036 is in the 17th percentile among its peer group of 1,128 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-6388.json
access.redhat.com / security/cve/CVE-2026-6388
bugzilla.redhat.com / show_bug.cgi