Excessive Permissions Vulnerability in IBM Turbonomic Application Resource Management
CVE-2026-6389
8.8HIGH
What is CVE-2026-6389?
IBM Turbonomic Application Resource Management has a vulnerability affecting the prometurbo agent versions 8.16.0 to 8.17.6, which provides excessive cluster-wide permissions. This flaw allows unauthorized users to gain unrestricted read access to all sensitive secrets. If an attacker compromises the operator or its associated service account, they can exfiltrate confidential credentials, escalate privileges, and possibly achieve complete compromise of the cluster, putting sensitive data and overall system integrity at significant risk.
Affected Version(s)
Turbonomic prometurbo agent 8.16.0 <= 8.17.6