{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/instana-agent-operator/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ibm:observability_with_instana:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.7,"id":"CVE-2026-19283"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Observability with Instana (Agent) (1.0.303-1.0.323)","Instana Agent Operator"],"_cs_severities":["high"],"_cs_tags":["vulnerability","kubernetes","openshift","credential-access"],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM Observability with Instana (Agent) versions 1.0.303 through 1.0.323 are affected by a security vulnerability within the Instana Agent Operator. The flaw stems from a lack of destination namespace validation when the operator performs secret synchronization operations. Specifically, the operator is susceptible to copying etcd mTLS client credentials from the protected 'openshift-etcd' system namespace into an arbitrary namespace controlled by an authenticated user. This exposure of sensitive security credentials facilitates unauthorized access to the cluster's etcd database. An attacker with sufficient privileges to interact with the Operator could potentially escalate their access or gain administrative control over the cluster by leveraging these credentials to bypass authentication and authorization controls within the Kubernetes environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the unauthorized disclosure of sensitive etcd mTLS credentials. This could lead to full cluster compromise as etcd holds the state and configuration of the entire OpenShift/Kubernetes environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all instances of IBM Observability with Instana (Agent) versions 1.0.303 through 1.0.323 currently deployed in the environment.\u003c/li\u003e\n\u003cli\u003eUpgrade the Instana Agent Operator to the remediated version provided by IBM to resolve the namespace validation flaw associated with CVE-2026-19283.\u003c/li\u003e\n\u003cli\u003eReview Kubernetes Role-Based Access Control (RBAC) configurations for the Instana Agent Operator to ensure it operates with the principle of least privilege, specifically restricting its ability to access secrets in the 'openshift-etcd' namespace.\u003c/li\u003e\n\u003cli\u003eAudit logs for unauthorized access or unexpected secret synchronization activity involving the Instana Agent Operator service account.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T17:27:05Z","date_published":"2026-09-04T17:27:05Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-19283/","summary":"IBM Instana Agent Operator versions 1.0.303 through 1.0.323 contain a vulnerability involving missing namespace validation that allows an authenticated attacker to copy sensitive etcd mTLS credentials to an attacker-controlled namespace.","title":"Information Disclosure Vulnerability in IBM Instana Agent Operator","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-19283/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ibm:instana_agent:1.0.303:*:*:*:*:*:*:*","cpe:2.3:a:ibm:instana_agent:1.0.323:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.6,"id":"CVE-2026-19274"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Instana Agent (1.0.303-1.0.323)","Instana Agent Operator"],"_cs_severities":["critical"],"_cs_tags":["privilege-escalation","kubernetes","cloud"],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM Observability with Instana Agent Operator (Build 1.0.303 through 1.0.323) contains a critical flaw in how it handles cluster-scoped RBAC objects for managed Kubernetes tenants. The operator keys specific RBAC resources solely by the name of the 'InstanaAgent' Custom Resource (CR) without incorporating namespace-based disambiguation. This design flaw allows an authenticated tenant within a multi-tenant Kubernetes environment to create a malicious 'InstanaAgent' CR using the same name as an existing, legitimate agent in a different namespace. Consequently, the operator mistakenly identifies the attacker-controlled resource as the intended target, allowing the attacker to silently overwrite shared 'ClusterRoleBinding' objects or delete them entirely. This behavior enables unauthorized privilege escalation or the permanent disruption of monitoring services for victim agents by revoking their cluster-level permissions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a malicious tenant to hijack cluster-level RBAC permissions assigned to the Instana Agent Operator or disrupt monitoring for other tenants. In a multi-tenant Kubernetes cluster, this can lead to unauthorized access to cluster resources or significant denial-of-service of the observability platform, impacting the integrity and availability of security and performance monitoring data.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security and infrastructure teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the IBM Instana Agent Operator to a version beyond 1.0.323 where namespace disambiguation for CRs is implemented to address CVE-2026-19274.\u003c/li\u003e\n\u003cli\u003eAudit Kubernetes clusters for existing 'InstanaAgent' CRs across different namespaces that share identical names to identify potential conflict indicators.\u003c/li\u003e\n\u003cli\u003eImplement restrictive Kubernetes RBAC policies that prevent untrusted tenants from creating or modifying custom resources associated with the Instana Agent Operator.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T17:26:38Z","date_published":"2026-09-04T17:26:38Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ibm-instana-rbac-hijack/","summary":"An authenticated tenant can perform privilege escalation in Kubernetes clusters using IBM Instana Agent Operator (Build 1.0.303 through 1.0.323) by creating a malicious Custom Resource that overwrites shared cluster-level RBAC objects.","title":"IBM Instana Agent Operator RBAC Hijacking Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-09-ibm-instana-rbac-hijack/"}],"language":"en","title":"CraftedSignal Threat Feed - Instana Agent Operator","version":"https://jsonfeed.org/version/1.1"}