Description
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable to prototype pollution through its configuration normalization API.
Published: 2026-07-28
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Observability with Instana Agent is vulnerable to prototype pollution in the @instana/core configuration normalization API. The flaw allows an attacker who can supply configuration data to modify JavaScript object prototypes, potentially changing program behavior or state. This weakness is classified as CWE-1321 and rated with a CVSS score of 7.3, indicating a high severity impact primarily on data integrity and confidentiality.

Affected Systems

IBM Observability with Instana Agent from Build 1.0.303 through 1.0.320 is affected. The vulnerable component is @instana/core version 6.2.1 used in the Agent.

Risk and Exploitability

The EPSS score of less than 1 % indicates a low likelihood of exploitation in the near term, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be through configuration data supplied to the Agent’s normalization routine, which could be via internal configuration services or exposed APIs. An attacker who can influence this input could alter the Agent’s execution context or data, but the CVE description does not state that arbitrary code execution is possible. The high CVSS score still warrants prompt remediation.

Generated by OpenCVE AI on August 4, 2026 at 23:27 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing these vulnerabilities now by updating IBM Observability with Instana to the latest release as described here: https://www.ibm.com/docs/en/instana-observability?topic=agents-updating-host Affected Product(s)Version(s)Remediation/Fixes/InstructionsIBM Observability with Instana (Agent)Build 1.0.303 to 1.0.320Build 1.0.321


OpenCVE Recommended Actions

  • Update IBM Observability with Instana Agent to Build 1.0.321 or newer following IBM’s update instructions.
  • Ensure that only trusted, validated configuration data reaches the Agent’s normalization API, applying input validation or sandboxing to mitigate prototype pollution.
  • If an immediate update is not possible, restrict access to the configuration interfaces or isolate the Agent so that external configuration sources are blocked until the vulnerability is fixed.

Generated by OpenCVE AI on August 4, 2026 at 23:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Ibm observability With Instana
Vendors & Products Ibm observability With Instana

Wed, 29 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable to prototype pollution through its configuration normalization API.
Title IBM Instana Observability is affected by multiple Prototype Pollution within Instana Agent container image
First Time appeared Ibm
Ibm observability With Instana Agent
Weaknesses CWE-1321
CPEs cpe:2.3:a:ibm:observability_with_instana_agent:1.0.320:*:*:*:*:*:*:*
cpe:2.3:a:ibm:observability_with_instana_agent:build:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm observability With Instana Agent
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L'}


Subscriptions

Ibm Observability With Instana Observability With Instana Agent
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-29T14:10:41.839Z

Reserved: 2026-07-06T18:19:15.930Z

Link: CVE-2026-14893

cve-icon Vulnrichment

Updated: 2026-07-29T14:10:38.079Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-28T21:17:26.193

Modified: 2026-07-30T14:08:40.373

Link: CVE-2026-14893

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T23:30:15Z

Weaknesses
  • CWE-1321

    Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')