Database/Container, Kubernetes & orchestration
OpenShift GitOps: namespace admin can escalate via ArgoCD CRs to root on control-plane nodes
Impact
A user who only holds admin rights inside one namespace can create an ArgoCD custom resource that causes the operator to grant it permissions in other namespaces, including privileged ones. From there the attacker schedules privileged workloads on master nodes, which is effectively cluster root. On a GPU cluster this collapses the boundary between tenant namespaces: whoever owns one project namespace can reach the kubelet credentials, node secrets and GPU device plugins of every other tenant, and can place a privileged pod on any node in the fleet. Red Hat scores it 9.1 with scope change, and the attack needs no node-level foothold - only a namespace the tenant already legitimately administers.
Who can reach it
Authenticated namespace administrator (or anyone who can create ArgoCD CRs in a namespace they control) reaching the cluster API. No node access and no cluster-level role required.
What to do
Patch the GitOps operator to the fixed build for your stream via RHSA-2025:23203 / 23206 / 23207 (GitOps 1.16-1.18) or RHSA-2026:1017. The operator and Argo CD controller pods restart in place; no node drain or reboot is involved. Until patched, restrict who can create ArgoCD custom resources in tenant namespaces and audit existing ones for cross-namespace targets.
References
Related entries
- MCE ClusterCurator: a namespace-scoped tenant admin can mint a cluster-admin ServiceAccount tokenCVE-2026-10059 · Red Hat Multicluster Engine for Kubernetes (ClusterCurator controller)Critical
- Envoy Gateway: path-normalization gap in the Lua validator lets submitted Lua read controller pod filesCVE-2026-53713 · Envoy Gateway controller (Lua validator, EnvoyExtensionPolicy)Critical
- Argo CD: Stored XSS via a `javascript:` link executes in an admin's browserCVE-2022-31035 · Argo CDCritical
- Argo CD: Improper authorization causes the API to accept tokens it should rejectCVE-2023-22482 · Argo CDCritical
- AKS Confidential Containers: elevation of privilege across the confidential container boundaryCVE-2024-21400 · Azure Kubernetes Service Confidential Containers (az confcom tooling)Critical
- Argo CD: Improper URL protocol filtering in link annotations enables client-side attacks against adminsCVE-2024-28175 · Argo CDCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.