CVE 8.8 HIGH

IBM Turbonomic Prometurbo agent used by IBM Turbonomic Application Resource Management is affected by a single vulnerability_CVE-2026-6389

8.8 / 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Description

IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cluster‑wide permissions, including unrestricted read access to all secrets. An attacker that compromises the operator or its service account can exfiltrate sensitive credentials, escalate privileges, and potentially achieve full cluster compromise.

AI Analysis

Excessive cluster-wide permissions grant unrestricted read access to all secrets, allowing attackers to exfiltrate sensitive credentials and escalate privileges.

Basic Information

ID CVE-2026-6389
Source ibm
Published Apr 30, 2026 at 21:17

Affected Product

Vendor IBM
Product Turbonomic prometurbo agent
Version 8.16.0
Affected Versions IBM Turbonomic prometurbo agent 8.16.0

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor IBM
Product Turbonomic prometurbo agent
Version 8.16.0-8.17.6

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.