GPU VulnDB

Database/Container, Kubernetes & orchestration

OpenShift GitOps: namespace admin can escalate via ArgoCD CRs to root on control-plane nodes

CVSS 9.1CVE-2025-13888Container, Kubernetes & orchestrationcurated

Impact

A user who only holds admin rights inside one namespace can create an ArgoCD custom resource that causes the operator to grant it permissions in other namespaces, including privileged ones. From there the attacker schedules privileged workloads on master nodes, which is effectively cluster root. On a GPU cluster this collapses the boundary between tenant namespaces: whoever owns one project namespace can reach the kubelet credentials, node secrets and GPU device plugins of every other tenant, and can place a privileged pod on any node in the fleet. Red Hat scores it 9.1 with scope change, and the attack needs no node-level foothold - only a namespace the tenant already legitimately administers.

Who can reach it

Authenticated namespace administrator (or anyone who can create ArgoCD CRs in a namespace they control) reaching the cluster API. No node access and no cluster-level role required.

What to do

Patch the GitOps operator to the fixed build for your stream via RHSA-2025:23203 / 23206 / 23207 (GitOps 1.16-1.18) or RHSA-2026:1017. The operator and Argo CD controller pods restart in place; no node drain or reboot is involved. Until patched, restrict who can create ArgoCD custom resources in tenant namespaces and audit existing ones for cross-namespace targets.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.