Description
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scoped RBAC objects being keyed solely by the bare CR name with no namespace disambiguation, allowing a same-named `InstanaAgent` CR in an attacker-controlled namespace to silently overwrite the shared `ClusterRoleBinding` or delete it outright and revoke the victim agent's cluster monitoring access.
Published: 2026-09-04
Score: 9.6 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is that the Instana Agent Operator constructs cluster‑scoped RBAC objects keyed only by the name of the InstanaAgent custom resource, with no namespace disambiguation. An attacker who can create an InstanaAgent resource within the same Kubernetes cluster can employ a same‑named InstanaAgent CR in an attacker‑controlled namespace to silently overwrite the shared ClusterRoleBinding that grants cluster‑monitoring permissions to the victim agent, or delete it outright. This allows the attacker to hijack the victim’s monitoring rights or permanently remove the victim’s ability to monitor the cluster. The weakness is a privilege‑escalation vulnerability (CWE‑284).

Affected Systems

IBM Observability with Instana (Agent) builds 1.0.303 through 1.0.323 are vulnerable. The recommended remediation is to update to the latest release of IBM Observability with Instana, which removes the flaw. No other IBM products are specified as affected in the CNA data.

Risk and Exploitability

The CVSS score of 9.6 marks this as a Critical vulnerability. Although the EPSS score is not available, the lack of measurement does not mitigate the inherent risk. The vulnerability is not listed in CISA KEV, but the nature of the flaw— allowing an authenticated Kubernetes tenant to overwrite or delete cluster‑level RBAC permissions—means an attacker with moderate cluster access could inflict significant damage. An attacker must have the ability to create or delete InstanaAgent CRs in the cluster, a realistic capability in many multi‑tenant scenarios.

Generated by OpenCVE AI on September 4, 2026 at 18:21 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing these vulnerabilities now by updating IBM Observability with Instana to the latest release as described here: https://www.ibm.com/docs/en/instana-observability/saas?topic=agents-updating-host Affected Product(s)Version(s)Remediation/Fixes/InstructionsIBM Observability with Instana (Agent)Build 1.0.303 to 1.0.323Build 1.0.324


OpenCVE Recommended Actions

  • Upgrade IBM Observability with Instana (Agent) to the latest release, which removes the vulnerability
  • Ensure that InstanaAgent custom resources are created with unique names and, where possible, enforce namespace isolation for CRs that influence cluster‑level RBAC objects
  • Verify existing ClusterRoleBinding objects and restrict permission changes to trusted administrators, monitoring for unauthorized modifications

Generated by OpenCVE AI on September 4, 2026 at 18:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scoped RBAC objects being keyed solely by the bare CR name with no namespace disambiguation, allowing a same-named `InstanaAgent` CR in an attacker-controlled namespace to silently overwrite the shared `ClusterRoleBinding` or delete it outright and revoke the victim agent's cluster monitoring access.
Title IBM Instana Observability is affected by multiple vulnerabilities within Instana Agent container image
First Time appeared Ibm
Ibm observability With Instana Agent
Weaknesses CWE-284
CPEs cpe:2.3:a:ibm:observability_with_instana_agent:1.0.323:*:*:*:*:*:*:*
cpe:2.3:a:ibm:observability_with_instana_agent:build:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm observability With Instana Agent
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H'}


Subscriptions

Ibm Observability With Instana Agent
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-04T17:28:51.304Z

Reserved: 2026-08-07T14:40:58.421Z

Link: CVE-2026-19274

cve-icon Vulnrichment

Updated: 2026-09-04T17:28:47.585Z

cve-icon NVD

Status : Received

Published: 2026-09-04T16:17:21.650

Modified: 2026-09-04T18:17:51.260

Link: CVE-2026-19274

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T18:30:04Z

Weaknesses