PT-2026-33180 · Unknown · Argocd Image Updater

Published

2026-04-15

·

Updated

2026-04-16

·

CVE-2026-6388

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions ArgoCD Image Updater (affected versions not specified)
Description An issue in multi-tenant environments allows an attacker with permissions to create or modify an ImageUpdater resource to bypass namespace boundaries. Due to insufficient validation, an attacker can trigger unauthorized image updates on applications managed by other tenants, leading to cross-namespace privilege escalation and impacting application integrity.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Enforce strict AppProject isolation. Restrict access to ImageUpdater resources.

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6388

Affected Products

Argocd Image Updater