Description
IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cluster‑wide permissions, including unrestricted read access to all secrets. An attacker that compromises the operator or its service account can exfiltrate sensitive credentials, escalate privileges, and potentially achieve full cluster compromise.
Published: 2026-04-30
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Turbonomic Prometurbo agent versions 8.16.0 through 8.17.6 grant excessive cluster‑wide permissions, allowing an attacker that has compromised the operator or its service account to read all secrets without restriction. This flaw enables the exfiltration of sensitive credentials, escalates privileges, and can ultimately lead to complete cluster compromise. The vulnerability is a classic example of the category identified by CWE‑269, where misuse of privilege permissions exposes critical data.

Affected Systems

The affected product is IBM Turbonomic Prometurbo agent, with security issues identified in releases 8.16.0, 8.17.6, and any intermediary versions. IBM has released version 8.18.0, which includes the necessary fixes; installation instructions for upgrading are provided in the IBM Turbonomic documentation. The vulnerability does not appear in any older or newer versions outside that range.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity, and while an EPSS score is not available, the lack of listing in the CISA KEV catalog suggests no publicly known exploits yet. The attack vector is inferred to be within the cluster; an attacker who gains the operator’s service account or decrypts credentials in the cluster can exploit this flaw. Once the attacker obtains unrestricted read access to secrets, they can exfiltrate credentials or elevate privileges to achieve full control of the cluster infrastructure.

Generated by OpenCVE AI on May 2, 2026 at 00:13 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by re-installing a version of prometurbo with the required fixes. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM Turbonomic prometurbo agent8.18.0 Follow the installation instructions https://www.ibm.com/docs/en/tarm/8.19.4 from the IBM Turbonomic documentation


OpenCVE Recommended Actions

  • Install the latest Turbonomic Prometurbo agent (8.18.0 or later) following the IBM installation guide to apply the vendor‑provided fix.
  • Restrict the operator’s service account to the principle of least privilege by removing cluster‑wide read permissions and limiting access to only the namespaces required for normal operations.
  • Audit and harden network access for the operator’s service account to prevent unintended external connections, ensuring it can only be reached by authorized components within the cluster.

Generated by OpenCVE AI on May 2, 2026 at 00:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 01 May 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Apr 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cluster‑wide permissions, including unrestricted read access to all secrets. An attacker that compromises the operator or its service account can exfiltrate sensitive credentials, escalate privileges, and potentially achieve full cluster compromise.
Title IBM Turbonomic Prometurbo agent used by IBM Turbonomic Application Resource Management is affected by a single vulnerability
First Time appeared Ibm
Ibm turbonomic Prometurbo Agent
Weaknesses CWE-269
CPEs cpe:2.3:a:ibm:turbonomic_prometurbo_agent:8.16.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:turbonomic_prometurbo_agent:8.17.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm turbonomic Prometurbo Agent
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Ibm Turbonomic Prometurbo Agent
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-05-01T16:37:57.048Z

Reserved: 2026-04-15T19:41:36.801Z

Link: CVE-2026-6389

cve-icon Vulnrichment

Updated: 2026-05-01T16:37:52.894Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-30T22:16:26.207

Modified: 2026-05-01T15:27:15.287

Link: CVE-2026-6389

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T00:15:06Z

Weaknesses