Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-6389

Опубликовано: 30 апр. 2026
Источник: nvd
CVSS3: 8.8
CVSS3: 7.8
EPSS Низкий

Описание

IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cluster‑wide permissions, including unrestricted read access to all secrets. An attacker that compromises the operator or its service account can exfiltrate sensitive credentials, escalate privileges, and potentially achieve full cluster compromise.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ibm:turbonomic_prometurbo_agent:*:*:*:*:*:*:*:*
Версия от 8.16.0 (включая) до 8.18.0 (исключая)

EPSS

Процентиль: 1%
0.00106
Низкий

8.8 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-269
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 8.8
github
3 месяца назад

IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cluster‑wide permissions, including unrestricted read access to all secrets. An attacker that compromises the operator or its service account can exfiltrate sensitive credentials, escalate privileges, and potentially achieve full cluster compromise.

EPSS

Процентиль: 1%
0.00106
Низкий

8.8 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-269
NVD-CWE-noinfo