ZeroHour

CVE-2026-19283

IBM Instana Agent Operator missing namespace validation leaks etcd mTLS credentials

CVSS 3.1
7.7 high
EPSS
<1%p23
Published
()
Modified
AI analysis

IBM Observability with Instana's Agent Operator, shipped in agent builds 1.0.303 through 1.0.323, fails to validate the destination namespace when copying the OpenShift etcd mTLS client credentials out of the openshift-etcd system namespace (CWE-863, incorrect authorization). An authenticated remote attacker with low privileges who controls a namespace on the same cluster can have those etcd mTLS client credentials copied into the attacker-controlled namespace and obtain them. With the credentials, the attacker can authenticate to the cluster's etcd datastore and read sensitive cluster data, producing a high confidentiality impact with no integrity or availability impact (CVSS 3.1 score 7.7, scope-changed). Only organizations running the Instana agent on OpenShift clusters with agent builds 1.0.303 through 1.0.323 are exposed. There are no known public exploits, PoCs, or CISA KEV listings, and EPSS estimates only about a 0.3% probability of exploitation in the next 30 days.

What to do: Upgrade Instana agents to a build newer than 1.0.323 per IBM's security advisory, which lists the fixed build. Audit cluster namespaces for copies of the openshift-etcd mTLS client credentials and rotate the etcd client certificates if any were copied into untrusted namespaces. Until patched, limit namespace creation and low-privileged access for tenants that could redirect the credential copy.

Affected
IBM Observability with Instana (Agent) - IBM Instana Agent OperatorBuild 1.0.303 through 1.0.323 (deployed on OpenShift clusters)
Estimated exposure
unknown - plausibly thousands of OpenShift-based Instana deployments at most, given the narrow 1.0.303-1.0.323 build window (no public install-base data) — No public active-install or internet-exposed device counts exist for IBM Instana agent builds, so the estimate rests on Instana being an enterprise APM with a limited customer base and on the flaw requiring a narrow recent build range plus…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying etcd mTLS client credentials from the openshift-etcd system namespace into an attacker-controlled namespace.

Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.