No advisories yet.
Solution
IBM strongly recommends addressing the vulnerability now by re-installing a version of prometurbo with the required fixes. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM Turbonomic prometurbo agent8.18.0 Follow the installation instructions https://www.ibm.com/docs/en/tarm/8.19.4 from the IBM Turbonomic documentation
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7270720 |
|
Thu, 30 Apr 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cluster‑wide permissions, including unrestricted read access to all secrets. An attacker that compromises the operator or its service account can exfiltrate sensitive credentials, escalate privileges, and potentially achieve full cluster compromise. | |
| Title | IBM Turbonomic Prometurbo agent used by IBM Turbonomic Application Resource Management is affected by a single vulnerability | |
| First Time appeared |
Ibm
Ibm turbonomic Prometurbo Agent |
|
| Weaknesses | CWE-269 | |
| CPEs | cpe:2.3:a:ibm:turbonomic_prometurbo_agent:8.16.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:turbonomic_prometurbo_agent:8.17.6:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm turbonomic Prometurbo Agent |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-04-30T21:17:06.371Z
Reserved: 2026-04-15T19:41:36.801Z
Link: CVE-2026-6389
No data.
Status : Received
Published: 2026-04-30T22:16:26.207
Modified: 2026-04-30T22:16:26.207
Link: CVE-2026-6389
No data.
OpenCVE Enrichment
No data.