Research & Tools · Misconfiguration

OperTraitor Exposes Kubernetes Operators With Broad Rights

Unit 42 released OperTraitor, an open-source analyzer for Kubernetes operator RBAC, and used it in two case studies to flag excessive permissions in OperatorHub, including a high-severity IBM Turbonomic issue and cluster-wide secrets access. The same catalog also held abandoned components that still look deployable.

The core problem is the service account behind the operator: if its RBAC grants wildcard or cluster-wide rights, the automation can do far more than its documented job. In practice, that turns a convenience component into a standing control-plane token, so reviewing the app version alone can miss the real exposure.

For teams that rely on service-account-based automation in Kubernetes, the lasting risk sits in the granted privileges and in old operator listings that remain available in registries like OperatorHub. If those bindings are broad, compromise or misuse of the operator can reach secrets and RBAC controls across the cluster even when the software itself looks routine.

1 source · Sep 29

Timeline

Sources

Part of the PlainSec briefing for 2026-09-29

Every edition of this story: OperTraitor Exposes Kubernetes Operators With Broad Rights