Research · 16h ago
Unit 42 released OperTraitor, an open-source analyzer for Kubernetes operator RBAC, and used it in two case studies to flag excessive permissions in OperatorHub, including a high-severity IBM Turbonomic issue and cluster-wide secrets access. The same catalog also held abandoned components that still look deployable.
The core problem is the service account behind the operator: if its RBAC grants wildcard or cluster-wide rights, the automation can do far more than its documented job. In practice, that turns a convenience component into a standing control-plane token, so reviewing the app version alone can miss the real exposure.
For teams that rely on service-account-based automation in Kubernetes, the lasting risk sits in the granted privileges and in old operator listings that remain available in registries like OperatorHub. If those bindings are broad, compromise or misuse of the operator can reach secrets and RBAC controls across the cluster even when the software itself looks routine.
1 source covering this story
OperTraitors: How Kubernetes Operators Betray Your Security Posture
We introduce OperTraitor, a tool to audit privileges of Kubernetes operators, identify excessive RBAC risks, and secure non-human identities.
Part of the PlainSec briefing for 2026-09-29