{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/instana/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-14893"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["IBM Observability with Instana (Agent) Build 1.0.303","IBM Observability with Instana (Agent) Build 1.0.320"],"_cs_severities":["high"],"_cs_tags":["vulnerability","prototype-pollution","nodejs","instana"],"_cs_type":"advisory","_cs_vendors":["IBM"],"content_html":"\u003cp\u003eIBM has disclosed a high-severity prototype pollution vulnerability, CVE-2026-14893, affecting its Observability with Instana (Agent) product. Specifically, the IBM Instana Node.js tracer component, \u003ccode\u003e@instana/core\u003c/code\u003e version 6.2.1, is susceptible to this flaw. The vulnerability resides within the component's configuration normalization API, which can be exploited by an attacker to improperly control modification of object prototype attributes. This allows for manipulation of application behavior and could lead to data integrity issues. The affected agent builds range from 1.0.303 through 1.0.320. This vulnerability has a CVSS v3.1 Base Score of 7.3, indicating a significant risk, particularly due to its high impact on integrity.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003cp\u003e(No specific attack chain details are provided in the source material for this vulnerability. The NVD entry describes a vulnerability, not an observed exploitation sequence.)\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability, rated with a CVSS 3.1 Base Score of 7.3 (High), primarily impacts the integrity of the affected systems. Successful exploitation of CVE-2026-14893 could allow an attacker to alter the behavior of the Node.js application or component by manipulating its prototype chain. This could lead to unauthorized modification of application data, configuration settings, or even execution flow, potentially causing unreliable operations or facilitating further compromise. The confidentiality and availability impacts are rated as low. The NVD entry does not specify the number of victims or targeted sectors.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-14893 immediately by updating IBM Observability with Instana (Agent) to a remediated version beyond 1.0.320, as detailed in the IBM support advisory reference.\u003c/li\u003e\n\u003cli\u003eReview the IBM support page at \u003ccode\u003ehttps://www.ibm.com/support/pages/node/7281349\u003c/code\u003e for specific upgrade instructions and mitigation strategies.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T21:24:48Z","date_published":"2026-07-28T21:24:48Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-14893/","summary":"A high-severity prototype pollution vulnerability, CVE-2026-14893, exists in the IBM Instana Node.js tracer component (@instana/core version 6.2.1) affecting IBM Observability with Instana Agent builds 1.0.303 through 1.0.320, allowing an attacker to modify critical application behavior through the configuration normalization API.","title":"IBM Instana Node.js Tracer Vulnerable to Prototype Pollution (CVE-2026-14893)","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-14893/"}],"language":"en","title":"CraftedSignal Threat Feed - Instana","version":"https://jsonfeed.org/version/1.1"}