CVE-2026-19283
7.7IBM · Observability with Instana (Agent)
An authentication-based authorization flaw in IBM Observability with Instana allows an attacker to misappropriate etcd mTLS credentials by bypassing namespace validation.
Executive summary
A high-severity authorization vulnerability in IBM Observability with Instana (Agent) allows authenticated remote attackers to exfiltrate sensitive etcd mTLS credentials.
Vulnerability
The vulnerability is an incorrect authorization flaw (CWE-863) where the Instana Agent Operator fails to validate the destination namespace during the copying of etcd mTLS client credentials. This allows an authenticated remote attacker to move sensitive credentials from the protected openshift-etcd namespace into an attacker controlled namespace.
Business impact
The compromise of etcd mTLS credentials poses a significant risk to the integrity and confidentiality of the entire OpenShift cluster. With these credentials, an attacker could potentially gain unauthorized access to the cluster backend, leading to complete cluster compromise, data exfiltration, or service disruption. Given the CVSS score of 7.7, this is a high-priority risk that threatens the security posture of the underlying container orchestration environment.
Remediation
Immediate Action: Update the IBM Observability with Instana (Agent) to Build 1.0.324 or later as specified in the official IBM security advisory.
Proactive Monitoring: Review cluster access logs for unauthorized namespace access attempts and monitor for unexpected activity involving the etcd service or sensitive secret resources.
Compensating Controls: Restrict administrative access to the Instana Agent Operator and ensure strict Role Based Access Control (RBAC) policies are enforced to limit the impact of compromised service accounts.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability represents a significant risk to cluster-level security due to the potential for credential theft. Administrators should prioritize the update to Build 1.0.324 across all affected environments immediately. Failure to patch may allow attackers who have gained low-level access to the system to escalate their footprint and compromise the core orchestration layer.