CVE-2026-19283
IBM Instana Agent Operator missing namespace validation leaks etcd mTLS credentials
IBM Observability with Instana's Agent Operator, shipped in agent builds 1.0.303 through 1.0.323, fails to validate the destination namespace when copying the OpenShift etcd mTLS client credentials out of the openshift-etcd system namespace (CWE-863, incorrect authorization). An authenticated remote attacker with low privileges who controls a namespace on the same cluster can have those etcd mTLS client credentials copied into the attacker-controlled namespace and obtain them. With the credentials, the attacker can authenticate to the cluster's etcd datastore and read sensitive cluster data, producing a high confidentiality impact with no integrity or availability impact (CVSS 3.1 score 7.7, scope-changed). Only organizations running the Instana agent on OpenShift clusters with agent builds 1.0.303 through 1.0.323 are exposed. There are no known public exploits, PoCs, or CISA KEV listings, and EPSS estimates only about a 0.3% probability of exploitation in the next 30 days.
What to do: Upgrade Instana agents to a build newer than 1.0.323 per IBM's security advisory, which lists the fixed build. Audit cluster namespaces for copies of the openshift-etcd mTLS client credentials and rotate the etcd client certificates if any were copied into untrusted namespaces. Until patched, limit namespace creation and low-privileged access for tenants that could redirect the credential copy.
| IBM Observability with Instana (Agent) - IBM Instana Agent Operator | Build 1.0.303 through 1.0.323 (deployed on OpenShift clusters) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying etcd mTLS client credentials from the openshift-etcd system namespace into an attacker-controlled namespace.
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.