Excessive Permissions Vulnerability in IBM Turbonomic Application Resource Management
CVE-2026-6389

8.8HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
30 April 2026

What is CVE-2026-6389?

IBM Turbonomic Application Resource Management has a vulnerability affecting the prometurbo agent versions 8.16.0 to 8.17.6, which provides excessive cluster-wide permissions. This flaw allows unauthorized users to gain unrestricted read access to all sensitive secrets. If an attacker compromises the operator or its associated service account, they can exfiltrate confidential credentials, escalate privileges, and possibly achieve complete compromise of the cluster, putting sensitive data and overall system integrity at significant risk.

Affected Version(s)

Turbonomic prometurbo agent 8.16.0 <= 8.17.6

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability was reported to IBM by Lior Yakim.
.