CVE-2025-13888Critical· 9.1▾ MidnightA flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that trick the system into granting them elevated permissions in other namespaces, including privileged namespaces. An authenticated attacker…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.7%
A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that trick the system into granting them elevated permissions in other namespaces, including privileged namespaces. An authenticated attacker can then use these elevated permissions to create privileged workloads that run on master nodes, effectively giving them root access to the entire cluster.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102129High· 7.2A user-provisioning interface in Kiteworks Core did not verify that the requesting administrator was entitled to grant the role being assigned
CVE-2025-69179Critical· 9.8Unauthenticated Privilege Escalation in Support Ticket Management System <= 1.9 versions.
CVE-2025-69138High· 8.8Subscriber Privilege Escalation in Genemy <= 1.6.6 versions.
CVE-2026-103470Critical· 9.3In Internet2 Grouper before 7.5.1 (in some configurations), a user who is allowed to create or edit rules in the User Interface can escalate privileges.
CVE-2026-94178High· 7.5Subscriber Privilege Escalation in Import and export users and customers <= 2.5.2 versions.
CVE-2026-96350Critical· 9.8Subscriber Privilege Escalation in Estatik <= 4.3.5 versions.