IBMCVE-2026-19283
IBM Observability with Instana (Agent): information disclosure
High7.7CVE-2026-19283 · Published Sep 4, 2026 · updated Sep 10, 2026
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying etcd mTLS client credentials from the openshift-etcd system namespace into an attacker-controlled namespace.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Observability with Instana (Agent) Product | >= Build 1.0.303, <= 1.0.323 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-863
More IBM advisories
All IBM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 4 | IBM i: improper authorization | High8.1 | No fix yet |
| Sep 4 | IBM i: improper authentication | High8.1 | No fix yet |
| Sep 4 | IBM i: integer overflow | Medium6.3 | No fix yet |
| Sep 4 | IBM ContextForge MCP Gateway: privilege escalation | High8.8 | No fix yet |
| Sep 4 | IBM ContextForge MCP Gateway - Translate utility: information disclosure | High7.4 | No fix yet |
| Sep 4 | IBM Langflow OSS: path traversal | Medium5.4 | No fix yet |