IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cluster‑wide permissions, including unrestricted read access to all secrets. An attacker that compromises the operator or its service account can exfiltrate sensitive credentials, escalate privileges, and potentially achieve full cluster compromise.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7270720 |
|
History
Tue, 05 May 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:ibm:turbonomic_prometurbo_agent:*:*:*:*:*:*:*:* |
Fri, 01 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Apr 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cluster‑wide permissions, including unrestricted read access to all secrets. An attacker that compromises the operator or its service account can exfiltrate sensitive credentials, escalate privileges, and potentially achieve full cluster compromise. | |
| Title | IBM Turbonomic Prometurbo agent used by IBM Turbonomic Application Resource Management is affected by a single vulnerability | |
| First Time appeared |
Ibm
Ibm turbonomic Prometurbo Agent |
|
| Weaknesses | CWE-269 | |
| CPEs | cpe:2.3:a:ibm:turbonomic_prometurbo_agent:8.16.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:turbonomic_prometurbo_agent:8.17.6:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm turbonomic Prometurbo Agent |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published: 2026-04-30T21:17:06.371Z
Updated: 2026-05-01T16:37:57.048Z
Reserved: 2026-04-15T19:41:36.801Z
Link: CVE-2026-6389
Updated: 2026-05-01T16:37:52.894Z
Status : Analyzed
Published: 2026-04-30T22:16:26.207
Modified: 2026-05-05T00:17:29.920
Link: CVE-2026-6389
No data.
ReportizFlow