Description
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying etcd mTLS client credentials from the openshift-etcd system namespace into an attacker-controlled namespace.
Published: 2026-09-04
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Sensitive Data Exposure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability occurs when the Instana Agent Operator copies etcd mTLS client credentials from the openshift‑etcd system namespace into an attacker‑controlled namespace without validating the destination. An attacker who has authenticated access to the cluster can therefore retrieve sensitive credentials that grant encryption and authentication privileges. The potential impact is the compromise of secrets that could allow further lateral movement or data exfiltration. The weakness is identified as CWE‑863, meaning an incorrect access control decision.

Affected Systems

IBM Observability with Instana (Agent) – affected builds include 1.0.303 through 1.0.323. Version 1.0.324 and later contain the fix.

Risk and Exploitability

The CVSS score of 7.7 indicates a high likelihood of exploitation in a restricted environment. EPSS data is not available, but the vulnerability is not listed in the CISA KEV catalog. Attackers need authenticated access to the cluster, which is often scoped to privileged users or service accounts with enough privileges to run the Instana Agent Operator. The risk to confidentiality is high because the attacker can read TLS client credentials that protect etcd communications.

Generated by OpenCVE AI on September 4, 2026 at 18:21 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing these vulnerabilities now by updating IBM Observability with Instana to the latest release as described here: https://www.ibm.com/docs/en/instana-observability/saas?topic=agents-updating-host Affected Product(s)Version(s)Remediation/Fixes/InstructionsIBM Observability with Instana (Agent)Build 1.0.303 to 1.0.323Build 1.0.324


OpenCVE Recommended Actions

  • Update IBM Observability with Instana to the latest release per IBM’s documentation.
  • If immediate patching is not possible, redeploy the Instana Agent Operator to isolate namespace traffic and enforce stricter namespace validation.
  • Review and tighten RBAC permissions for the Instana Agent Operator so it can only access the necessary system namespaces and nothing beyond its scope.

Generated by OpenCVE AI on September 4, 2026 at 18:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying etcd mTLS client credentials from the openshift-etcd system namespace into an attacker-controlled namespace.
Title IBM Instana Observability is affected by multiple vulnerabilities within Instana Agent container image
First Time appeared Ibm
Ibm observability With Instana Agent
Weaknesses CWE-863
CPEs cpe:2.3:a:ibm:observability_with_instana_agent:1.0.323:*:*:*:*:*:*:*
cpe:2.3:a:ibm:observability_with_instana_agent:build:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm observability With Instana Agent
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Ibm Observability With Instana Agent
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-10T21:00:35.137Z

Reserved: 2026-08-07T15:34:52.094Z

Link: CVE-2026-19283

cve-icon Vulnrichment

Updated: 2026-09-10T20:57:09.495Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-04T16:17:21.777

Modified: 2026-09-10T21:17:24.753

Link: CVE-2026-19283

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T22:15:06Z

Weaknesses