Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
IBM strongly recommends addressing the vulnerability now by re-installing a version of prometurbo with the required fixes. Product(s)Version(s) number and/or range Remediation/Fix/InstructionsIBM Turbonomic prometurbo agent8.18.0 Follow the installation instructions https://www.ibm.com/docs/en/tarm/8.19.4 from the IBM Turbonomic documentation
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7270720 |
|
Tue, 05 May 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:ibm:turbonomic_prometurbo_agent:*:*:*:*:*:*:*:* |
Fri, 01 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Apr 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cluster‑wide permissions, including unrestricted read access to all secrets. An attacker that compromises the operator or its service account can exfiltrate sensitive credentials, escalate privileges, and potentially achieve full cluster compromise. | |
| Title | IBM Turbonomic Prometurbo agent used by IBM Turbonomic Application Resource Management is affected by a single vulnerability | |
| First Time appeared |
Ibm
Ibm turbonomic Prometurbo Agent |
|
| Weaknesses | CWE-269 | |
| CPEs | cpe:2.3:a:ibm:turbonomic_prometurbo_agent:8.16.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:turbonomic_prometurbo_agent:8.17.6:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm turbonomic Prometurbo Agent |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-05-01T16:37:57.048Z
Reserved: 2026-04-15T19:41:36.801Z
Link: CVE-2026-6389
Updated: 2026-05-01T16:37:52.894Z
Status : Analyzed
Published: 2026-04-30T22:16:26.207
Modified: 2026-05-05T00:17:29.920
Link: CVE-2026-6389
No data.
OpenCVE Enrichment
Updated: 2026-05-05T03:00:10Z