<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Observability With Instana (Agent) (1.0.303-1.0.323) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/observability-with-instana-agent-1.0.303-1.0.323/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 04 Sep 2026 17:27:05 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/observability-with-instana-agent-1.0.303-1.0.323/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Information Disclosure Vulnerability in IBM Instana Agent Operator</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-19283/</link><pubDate>Fri, 04 Sep 2026 17:27:05 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-19283/</guid><description>IBM Instana Agent Operator versions 1.0.303 through 1.0.323 contain a vulnerability involving missing namespace validation that allows an authenticated attacker to copy sensitive etcd mTLS credentials to an attacker-controlled namespace.</description><content:encoded><![CDATA[<p>IBM Observability with Instana (Agent) versions 1.0.303 through 1.0.323 are affected by a security vulnerability within the Instana Agent Operator. The flaw stems from a lack of destination namespace validation when the operator performs secret synchronization operations. Specifically, the operator is susceptible to copying etcd mTLS client credentials from the protected 'openshift-etcd' system namespace into an arbitrary namespace controlled by an authenticated user. This exposure of sensitive security credentials facilitates unauthorized access to the cluster's etcd database. An attacker with sufficient privileges to interact with the Operator could potentially escalate their access or gain administrative control over the cluster by leveraging these credentials to bypass authentication and authorization controls within the Kubernetes environment.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in the unauthorized disclosure of sensitive etcd mTLS credentials. This could lead to full cluster compromise as etcd holds the state and configuration of the entire OpenShift/Kubernetes environment.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Identify all instances of IBM Observability with Instana (Agent) versions 1.0.303 through 1.0.323 currently deployed in the environment.</li>
<li>Upgrade the Instana Agent Operator to the remediated version provided by IBM to resolve the namespace validation flaw associated with CVE-2026-19283.</li>
<li>Review Kubernetes Role-Based Access Control (RBAC) configurations for the Instana Agent Operator to ensure it operates with the principle of least privilege, specifically restricting its ability to access secrets in the 'openshift-etcd' namespace.</li>
<li>Audit logs for unauthorized access or unexpected secret synchronization activity involving the Instana Agent Operator service account.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>kubernetes</category><category>openshift</category><category>credential-access</category></item></channel></rss>