Privilege Escalation Vulnerability in OpenShift GitOps by Red Hat
CVE-2025-13888
Key Information:
- Vendor
Red Hat-developer
- Status
- Vendor
- CVE Published:
- 15 December 2025
What is CVE-2025-13888?
A security flaw exists in OpenShift GitOps that enables namespace administrators to create ArgoCD Custom Resources (CRs) leading to unauthorized escalations of privileges across different namespaces. This can permit authenticated attackers to gain access to privileged workloads operating on master nodes, thereby potentially granting root-level access to the entire cluster. Proper patching and security measures are imperative to mitigate this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
gitops-operator 0 < 1.16.2
Red Hat OpenShift GitOps 1.16 sha256:c41c99f360a2515bce55c42e309e2c72500ba66d3a2c461412dee7de5ea9a9fa
Red Hat OpenShift GitOps 1.17 sha256:27e7a59bb5c5f60be7509e5f4f07f4181d62e6583a943c46f56f568bfc30c2c1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
