Aller au contenu

Fiche vulnérabilité

CVE-2026-6389 : faille élevée ibm turbonomic prometurbo agent (CVSS 7.8)

Description

IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cluster‑wide permissions, including unrestricted read access to all secrets. An attacker that compromises the operator or its service account can exfiltrate sensitive credentials, escalate privileges, and potentially achieve full cluster compromise.

En bref

Sévérité
Élevée (CVSS 7.8)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
30 avr. 2026
Dernière mise à jour
17 juin 2026

Produits concernés

  • ibm turbonomic prometurbo agent

Références

Rechercher une autre vulnérabilité dans la base CVE