IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying etcd mTLS client credentials from the openshift-etcd system namespace into an attacker-controlled namespace.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7286070 |
|
History
Fri, 04 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying etcd mTLS client credentials from the openshift-etcd system namespace into an attacker-controlled namespace. | |
| Title | IBM Instana Observability is affected by multiple vulnerabilities within Instana Agent container image | |
| First Time appeared |
Ibm
Ibm observability With Instana Agent |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:ibm:observability_with_instana_agent:1.0.323:*:*:*:*:*:*:* cpe:2.3:a:ibm:observability_with_instana_agent:build:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm observability With Instana Agent |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published: 2026-09-04T15:49:17.741Z
Updated: 2026-09-04T15:49:17.741Z
Reserved: 2026-08-07T15:34:52.094Z
Link: CVE-2026-19283
No data.
Status : Awaiting Analysis
Published: 2026-09-04T16:17:21.777
Modified: 2026-09-08T14:17:08.940
Link: CVE-2026-19283
No data.