High severity8.8NVD Advisory· Published Apr 30, 2026· Updated May 5, 2026
CVE-2026-6389
CVE-2026-6389
Description
IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cluster‑wide permissions, including unrestricted read access to all secrets. An attacker that compromises the operator or its service account can exfiltrate sensitive credentials, escalate privileges, and potentially achieve full cluster compromise.
Affected products
1- cpe:2.3:a:ibm:turbonomic_prometurbo_agent:*:*:*:*:*:*:*:*Range: >=8.16.0,<8.18.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.ibm.com/support/pages/node/7270720nvdVendor Advisory
News mentions
0No linked articles in our index yet.