New OperTraitors Tool Reveals Dangerous Privilege Escalation Paths in Kubernetes Operators
Palo Alto Networks released OperTraitor to flag Kubernetes operators granted excessive RBAC privileges.
Palo Alto Networks released OperTraitor, an open-source tool that compares Kubernetes operator RBAC with each operator's documented purpose and assigns a risk score from 1 to 10. It reviews local manifests and the OperatorHub catalog. More than 5% of examined operators requested excessive permissions, including paths toward cluster administrator. IBM's Prometurbo operator had cluster-wide get, list, and watch on Secrets; IBM fixed that as CVE-2026-6389 with CVSS 8.8. The Datadog operator was also flagged for broad Secrets and RBAC access, and Datadog published mitigations.