A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that trick the system into granting them elevated permissions in other namespaces, including privileged namespaces. An authenticated attacker can then use these elevated permissions to create privileged workloads that run on master nodes, effectively giving them root access to the entire cluster.
History

Tue, 16 Dec 2025 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Mon, 15 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift_gitops:1.16::el8
cpe:/a:redhat:openshift_gitops:1.17::el8
References

Mon, 15 Dec 2025 19:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift_gitops:1

Mon, 15 Dec 2025 19:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift_gitops:1

Mon, 15 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 15 Dec 2025 15:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that trick the system into granting them elevated permissions in other namespaces, including privileged namespaces. An authenticated attacker can then use these elevated permissions to create privileged workloads that run on master nodes, effectively giving them root access to the entire cluster.
Title Openshift-gitops-operator: openshift gitops: namespace admin cluster takeover via privileged jobs
First Time appeared Redhat
Redhat openshift Gitops
Weaknesses CWE-266
CPEs cpe:/a:redhat:openshift_gitops:1
cpe:/a:redhat:openshift_gitops:1.18::el8
Vendors & Products Redhat
Redhat openshift Gitops
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-12-15T20:10:59.040Z

Reserved: 2025-12-02T15:18:16.323Z

Link: CVE-2025-13888

cve-icon Vulnrichment

Updated: 2025-12-15T15:50:13.357Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-15T16:15:50.333

Modified: 2025-12-15T20:15:48.937

Link: CVE-2025-13888

cve-icon Redhat

Severity : Important

Publid Date: 2025-12-15T13:00:00Z

Links: CVE-2025-13888 - Bugzilla

cve-icon OpenCVE Enrichment

No data.