CVE-2026-19274 PUBLISHED

IBM Instana Observability is affected by multiple vulnerabilities within Instana Agent container image

Assigner: ibm
Reserved: 07.08.2026 Published: 04.09.2026 Updated: 04.09.2026

IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scoped RBAC objects being keyed solely by the bare CR name with no namespace disambiguation, allowing a same-named InstanaAgent CR in an attacker-controlled namespace to silently overwrite the shared ClusterRoleBinding or delete it outright and revoke the victim agent's cluster monitoring access.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
CVSS Score: 9.6

Product Status

Vendor IBM
Product Observability with Instana (Agent)
Versions
  • affected from Build 1.0.303 to 1.0.323 (incl.)

Solutions

IBM strongly recommends addressing these vulnerabilities now by updating IBM Observability with Instana to the latest release as described here:

https://www.ibm.com/docs/en/instana-observability/saas?topic=agents-updating-host

Affected Product(s)Version(s)Remediation/Fixes/InstructionsIBM Observability with Instana (Agent)Build 1.0.303 to 1.0.323Build 1.0.324

References

Problem Types

  • CWE-284 Improper Access Control CWE