CVE-2026-6388
ArgoCD Image Updater could allow an internal attacker to make unauthorized application updates.
Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.
An internal attacker can exploit a weakness in ArgoCD Image Updater to bypass security controls and modify applications belonging to other tenants. This unauthorized access allows them to force the deployment of unauthorized software, which compromises the integrity of critical business applications.