OperTraitors: How Kubernetes Operators Betray Your Security Posture
Nobody reads the ClusterRole before applying an operator, and that’s the whole finding. Unit 42 ran an LLM-based tool over OperatorHub and found slightly over 5% of operators requesting excessive privileges, some with implicit paths to cluster admin. IBM’s Prometurbo operator (CVE-2026-6389, CVSS 8.8) shipped a service account with cluster-wide read on secrets in every namespace. One bad operator image, and your DB credentials go with it.