OperTraitor Flags Excessive Kubernetes RBAC and IBM CVE-2026-6389
Unit 42's OperTraitor found more than 5% of assessed Kubernetes operators request excessive RBAC, including IBM CVE-2026-6389.
Palo Alto Networks Unit 42 released OperTraitor, an open-source LLM-powered tool that compares the documented purpose of OperatorHub and locally installed Kubernetes operators with the RBAC granted to their service accounts and assigns each a 1–10 risk score. The analysis found that more than 5% of assessed operators requested permissions beyond their documented purpose, including cluster-wide secret access and paths toward cluster-admin control. The tool identified CVE-2026-6389 (CVSS 8.8); Unit 42's report names IBM Turbonomic, while GBHackers and Cyber Security News describe an outdated IBM Prometurbo OperatorHub release that could get, list, and watch secrets cluster-wide, for which IBM published a bulletin on April 24, 2026. Datadog's operator was also flagged for cluster-wide secrets and ClusterRole permissions, and Datadog documented mitigations. Unit 42 warns that excessive service-account rights can turn trusted operators into silent backdoors, that stale OperatorHub builds can remain more permissive than current vendor channels, and that agentic LLM-driven operators could amplify misconfigurations, and it urges defenders to downscope operator service accounts.
- Palo Alto Networks Unit 42 released OperTraitor, an open-source LLM engine that scores OperatorHub and locally installed Kubernetes operators from 1 to 10 by comparing documented purpose with granted RBAC.
- More than 5% of assessed operators requested permissions beyond their documented purpose, including cluster-wide secret access and paths toward cluster-admin control.
- CVE-2026-6389 (CVSS 8.8) covers cluster-wide get, list, and watch on Secrets; Unit 42 names IBM Turbonomic, while later reports name an outdated IBM Prometurbo OperatorHub release.
- IBM published a bulletin for CVE-2026-6389 on April 24, 2026.
- Datadog's operator was flagged for cluster-wide secrets and ClusterRole permissions, and Datadog documented mitigations.
- Unit 42 also flagged a configuration granting cluster-wide secret access plus RBAC changes and urges defenders to downscope operator service accounts.
- Unit 42 warns that stale OperatorHub builds can stay more permissive than current vendor channels and that agentic LLM-driven operators could turn excessive RBAC into active cluster control.
Coverage timelineoldest first · each row is one article
- · 1d agoOperTraitors: How Kubernetes Operators Betray Your Security Posture
Palo Alto Unit 42· 61
Unit 42's OperTraitor flags overprivileged Kubernetes operators and found CVE-2026-6389 in IBM Turbonomic.
- · 17h agoOperTraitor Finds Kubernetes Operators With Cluster-Wide Secret Access and Admin Paths
GBHackers· 61
OperTraitor finds Kubernetes operators with excessive RBAC, including IBM CVE-2026-6389 cluster-wide secret access.
- · 16h agoNew OperTraitors Tool Reveals Dangerous Privilege Escalation Paths in Kubernetes Operators
Cyber Security News· 48
Vulnerabilities in this storyAll →
- CVE-2026-63897.8<1%IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cluster‑wide permissions, including…published · ibm turbonomic prometurbo agent
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-6389 | IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cluster‑wide permissions, including… IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cluster‑wide permissions, including unrestricted read access to all secrets. An attacker that compromises the operator or its service account can exfiltrate sensitive credentials, escalate privileges, and potentially achieve full cluster compromise. |