Get real-time updates on Telegram
CVE-2025-13888: gitops-operator 0 to before 1.16.2; +4 more affected products
CVE-2025-13888. CVSS 3.1 base score 9.1 (CRITICAL, Vendor/CNA). EPSS 0.00691 (percentile 0.51162), scored 2026-10-05.
Affected technology
gitops-operator · 0 to before 1.16.2
redhat-developer
Red Hat OpenShift GitOps 1.16 · Exact affected versions not specified by the source
Red Hat
Red Hat OpenShift GitOps 1.17 · Exact affected versions not specified by the source
Red Hat
Red Hat OpenShift GitOps 1.18 · Exact affected versions not specified by the source
Red Hat
Red Hat OpenShift GitOps · Exact affected versions not specified by the source
Red Hat
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · High privileges required · No user interaction required
What an attacker can do
An authenticated attacker can then use these elevated permissions to create privileged workloads that run on master nodes, effectively giving them root access to the entire cluster. Vendor/CNA’s CVSS 3.1 assessment (base score 9.1/10) rates confidentiality, integrity and availability impact as high.
- CWE
- CWE-266
- CCR priority
- 36.6 /100 (P4)
- CVSS 3.1
- 9.1 /10 · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H · Vendor/CNA
- EPSS
- 0.00691 · percentile 0.51242 · 2026-10-06
- KEV
- no
Provenance
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-07 11:53:15.413517+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-07 11:49:32.540646+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2025-13888.html