OperTraitor Finds Kubernetes Operators With Cluster-Wide Secret Access and Admin Paths
OperTraitor finds Kubernetes operators with excessive RBAC, including IBM CVE-2026-6389 cluster-wide secret access.
Unit 42 described OperTraitor, an open-source LLM-powered tool that compares Kubernetes operator RBAC with each operator's stated purpose. More than 5% of assessed operators requested excessive rights, including cluster-wide secret access and paths toward cluster-admin control. An outdated IBM Prometurbo OperatorHub release could get, list, and watch secrets cluster-wide; IBM assigned CVE-2026-6389 (CVSS 8.8) and published a bulletin on April 24, 2026. Datadog's operator was also flagged for cluster-wide secrets and ClusterRole permissions, and Datadog documented mitigations.