CVE-2026-6389Disclosure(ibm / turbonomic_prometurbo_agent)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cluster‑wide permissions, including unrestricted read access to all secrets. An attacker that compromises the operator or its service account can exfiltrate sensitive credentials, escalate privileges, and potentially achieve full cluster compromise.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • turbonomic_prometurbo_agent

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-04-30); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
turbonomic_prometurbo_agent

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-30: 3Mentions · 2026-05-01: 1Mentions · 2026-09-29: 1Technical Details · 2026-04-30: 104-3005-0109-29
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-303
Disclosure2General1
2026-05-011
Disclosure1
Full discourse5 posts
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-6389 IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive c… CVSS 8.8 Full analysis → https://sec.kaitan.id/cves/CVE-2026-6389 #IBM #CyberSecurity #InfoSec

    Post summary

    The post announces a high‑severity vulnerability CVE‑2026‑6389 affecting IBM Turbonomic Prometurbo agent, provides a CVSS score of 8.8, and directs readers to a full analysis for more details.

    0001028
    460 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6389 IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cluster‑wide permissions, including unrestricted r… https://www.cve.org/CVERecord?id=CVE-2026-6389

    Post summary

    The tweet announces CVE-2026-6389, noting that IBM Turbonomic prometurbo agent versions 8.16.0‑8.17.6 grant excessive cluster‑wide permissions, but provides no PoC, exploit, or patch information.

    00010121
    57.4K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc

    TRC analysis reveals over 5% of Kubernetes operators contain excessive RBAC permissions, including CVE-2026-6389 in IBM Turbonomic granting cluster-wide secret access. Compromised operators can escalate privileges and move laterally across namespaces. Runtime segmentation helps limit blast radius of overprivileged service accounts. #CloudSecurity #ZeroTrust 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/kubernetes-operators-rbac-misconfiguration-cve-2026-6389

    0000044
    2.0K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    We have just added an important vulnerability affecting IBM Turbonomic Prometurbo Agent (CVE-2026-6389) https://vuldb.com/vuln/360400

    Post summary

    The text announces the discovery of CVE-2026-6389, affecting IBM Turbonomic Prometurbo Agent, and directs readers to a vulnerability database page for further details.

    0000062
    2.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-6389 Excessive Cluster Permissions in IBM Turbonomic Prometurbo... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6389 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet merely advertises a CVE by linking to a vulnerability details page without providing technical, exploitation, or patching information.

    0000033
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appibmturbonomic_prometurbo_agent---

Explore more