<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:ibm:instana_agent:1.0.323:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aibminstana_agent1.0.323/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 04 Sep 2026 17:26:38 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aibminstana_agent1.0.323/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>IBM Instana Agent Operator RBAC Hijacking Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-09-ibm-instana-rbac-hijack/</link><pubDate>Fri, 04 Sep 2026 17:26:38 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-ibm-instana-rbac-hijack/</guid><description>An authenticated tenant can perform privilege escalation in Kubernetes clusters using IBM Instana Agent Operator (Build 1.0.303 through 1.0.323) by creating a malicious Custom Resource that overwrites shared cluster-level RBAC objects.</description><content:encoded><![CDATA[<p>IBM Observability with Instana Agent Operator (Build 1.0.303 through 1.0.323) contains a critical flaw in how it handles cluster-scoped RBAC objects for managed Kubernetes tenants. The operator keys specific RBAC resources solely by the name of the 'InstanaAgent' Custom Resource (CR) without incorporating namespace-based disambiguation. This design flaw allows an authenticated tenant within a multi-tenant Kubernetes environment to create a malicious 'InstanaAgent' CR using the same name as an existing, legitimate agent in a different namespace. Consequently, the operator mistakenly identifies the attacker-controlled resource as the intended target, allowing the attacker to silently overwrite shared 'ClusterRoleBinding' objects or delete them entirely. This behavior enables unauthorized privilege escalation or the permanent disruption of monitoring services for victim agents by revoking their cluster-level permissions.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows a malicious tenant to hijack cluster-level RBAC permissions assigned to the Instana Agent Operator or disrupt monitoring for other tenants. In a multi-tenant Kubernetes cluster, this can lead to unauthorized access to cluster resources or significant denial-of-service of the observability platform, impacting the integrity and availability of security and performance monitoring data.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security and infrastructure teams:</p>
<ul>
<li>Upgrade the IBM Instana Agent Operator to a version beyond 1.0.323 where namespace disambiguation for CRs is implemented to address CVE-2026-19274.</li>
<li>Audit Kubernetes clusters for existing 'InstanaAgent' CRs across different namespaces that share identical names to identify potential conflict indicators.</li>
<li>Implement restrictive Kubernetes RBAC policies that prevent untrusted tenants from creating or modifying custom resources associated with the Instana Agent Operator.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>privilege-escalation</category><category>kubernetes</category><category>cloud</category></item></channel></rss>