Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
IBM strongly recommends addressing these vulnerabilities now by updating IBM Observability with Instana to the latest release as described here: https://www.ibm.com/docs/en/instana-observability/saas?topic=agents-updating-host Affected Product(s)Version(s)Remediation/Fixes/InstructionsIBM Observability with Instana (Agent)Build 1.0.303 to 1.0.323Build 1.0.324
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7286070 |
|
Fri, 04 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying etcd mTLS client credentials from the openshift-etcd system namespace into an attacker-controlled namespace. | |
| Title | IBM Instana Observability is affected by multiple vulnerabilities within Instana Agent container image | |
| First Time appeared |
Ibm
Ibm observability With Instana Agent |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:ibm:observability_with_instana_agent:1.0.323:*:*:*:*:*:*:* cpe:2.3:a:ibm:observability_with_instana_agent:build:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm observability With Instana Agent |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-09-04T15:49:17.741Z
Reserved: 2026-08-07T15:34:52.094Z
Link: CVE-2026-19283
No data.
Status : Received
Published: 2026-09-04T16:17:21.777
Modified: 2026-09-04T16:17:21.777
Link: CVE-2026-19283
No data.
OpenCVE Enrichment
Updated: 2026-09-04T18:30:04Z