ArgoCD Image Updater Cross-Namespace Privilege Escalation Vulnerability

Vulnerability

A vulnerability in ArgoCD Image Updater allows an attacker with permissions to create or modify ImageUpdater resources in a multi-tenant environment to bypass namespace boundaries. This exploitation of insufficient validation can trigger unauthorized image updates on applications managed by other tenants, leading to cross-namespace privilege escalation and compromising application integrity through unauthorized updates.

Impact

Exploitation of this vulnerability allows for cross-namespace privilege escalation, enabling unauthorized image updates on applications in other namespaces, which can disrupt application integrity.

Remediation

To address this vulnerability, ensure that AppProject resources enforce strict tenant isolation within Red Hat OpenShift GitOps environments. Additionally, restrict the permissions of the Argo CD Image Updater controller to designated namespaces only, and limit the ability to create or modify ImageUpdater resources to trusted administrators.

Added: Apr 15, 2026, 10:41 PM
Updated: Apr 15, 2026, 10:41 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.8
exploitability
4.8
remediation
0.0
relevance
6.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.