A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that trick the system into granting them elevated permissions in other namespaces, including privileged namespaces. An authenticated attacker can then use these elevated permissions to create privileged workloads that run on master nodes, effectively giving them root access to the entire cluster.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-pcqx-8qww-7f4v OpenShift GitOps authenticated attackers can obtain cluster root access through forged ArgoCD custom resources
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 24 Dec 2025 22:45:00 +0900


Tue, 16 Dec 2025 09:15:00 +0900

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Tue, 16 Dec 2025 05:15:00 +0900

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift_gitops:1.16::el8
cpe:/a:redhat:openshift_gitops:1.17::el8
References

Tue, 16 Dec 2025 04:45:00 +0900

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift_gitops:1

Tue, 16 Dec 2025 04:00:00 +0900

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift_gitops:1

Tue, 16 Dec 2025 01:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 16 Dec 2025 00:45:00 +0900

Type Values Removed Values Added
Description A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that trick the system into granting them elevated permissions in other namespaces, including privileged namespaces. An authenticated attacker can then use these elevated permissions to create privileged workloads that run on master nodes, effectively giving them root access to the entire cluster.
Title Openshift-gitops-operator: openshift gitops: namespace admin cluster takeover via privileged jobs
First Time appeared Redhat
Redhat openshift Gitops
Weaknesses CWE-266
CPEs cpe:/a:redhat:openshift_gitops:1
cpe:/a:redhat:openshift_gitops:1.18::el8
Vendors & Products Redhat
Redhat openshift Gitops
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-12-24T13:49:12.218Z

Reserved: 2025-12-02T15:18:16.323Z

Link: CVE-2025-13888

cve-icon Vulnrichment

Updated: 2025-12-15T15:50:13.357Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-15T16:15:50.333

Modified: 2025-12-24T14:15:47.170

Link: CVE-2025-13888

cve-icon Redhat

Severity : Important

Publid Date: 2025-12-15T13:00:00Z

Links: CVE-2025-13888 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses