PALO Alto Networks’ Unit 42 says Kubernetes operators frequently run with service accounts that have more privileges than their documented functions require, creating a route to wider cluster compromise if an operator is breached. Its open-source OperTraitor tool collects operator manifests from local installations and OperatorHub, uses an LLM to compare stated functionality with granted RBAC permissions, and assigns a risk score from 1 to 10.
In testing, Unit 42 found that slightly over 5% of operators requested excessive privileges, including potential paths to cluster-admin access. It also warned that OperatorHub and the Operator Lifecycle Manager can expose outdated or abandoned versions, even where vendors have published newer releases elsewhere.
One case involved IBM’s Prometurbo operator. Unit 42 found that version 8.17.6 used a cluster-wide role allowing its service account to get, list and watch secrets across namespaces. If compromised, the operator could expose service-account tokens, credentials, API keys and certificates. IBM fixed the issue following disclosure and published CVE-2026-6389, rated High with a CVSS score of 8.8.
Unit 42 also identified broad secret and RBAC permissions in the Datadog operator; Datadog said dynamic, user-defined secret names made tighter restrictions difficult and documented the rationale and mitigations.
The researchers recommend verifying operator sources and maintenance status, preferring current vendor releases, using namespace-scoped deployments where possible, auditing and reducing RBAC permissions, and monitoring Kubernetes audit logs for unusual service-account activity. They said LLM-enabled and agentic operators could amplify the consequences of excessive permissions by giving autonomous systems access to sensitive cluster resources.