<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Instana - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/instana/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 28 Jul 2026 21:24:48 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/instana/feed.xml" rel="self" type="application/rss+xml"/><item><title>IBM Instana Node.js Tracer Vulnerable to Prototype Pollution (CVE-2026-14893)</title><link>https://feed.craftedsignal.io/briefs/2026-07-cve-2026-14893/</link><pubDate>Tue, 28 Jul 2026 21:24:48 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-07-cve-2026-14893/</guid><description>A high-severity prototype pollution vulnerability, CVE-2026-14893, exists in the IBM Instana Node.js tracer component (@instana/core version 6.2.1) affecting IBM Observability with Instana Agent builds 1.0.303 through 1.0.320, allowing an attacker to modify critical application behavior through the configuration normalization API.</description><content:encoded><![CDATA[<p>IBM has disclosed a high-severity prototype pollution vulnerability, CVE-2026-14893, affecting its Observability with Instana (Agent) product. Specifically, the IBM Instana Node.js tracer component, <code>@instana/core</code> version 6.2.1, is susceptible to this flaw. The vulnerability resides within the component's configuration normalization API, which can be exploited by an attacker to improperly control modification of object prototype attributes. This allows for manipulation of application behavior and could lead to data integrity issues. The affected agent builds range from 1.0.303 through 1.0.320. This vulnerability has a CVSS v3.1 Base Score of 7.3, indicating a significant risk, particularly due to its high impact on integrity.</p>
<h2 id="attack-chain">Attack Chain</h2>
<p>(No specific attack chain details are provided in the source material for this vulnerability. The NVD entry describes a vulnerability, not an observed exploitation sequence.)</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability, rated with a CVSS 3.1 Base Score of 7.3 (High), primarily impacts the integrity of the affected systems. Successful exploitation of CVE-2026-14893 could allow an attacker to alter the behavior of the Node.js application or component by manipulating its prototype chain. This could lead to unauthorized modification of application data, configuration settings, or even execution flow, potentially causing unreliable operations or facilitating further compromise. The confidentiality and availability impacts are rated as low. The NVD entry does not specify the number of victims or targeted sectors.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Patch CVE-2026-14893 immediately by updating IBM Observability with Instana (Agent) to a remediated version beyond 1.0.320, as detailed in the IBM support advisory reference.</li>
<li>Review the IBM support page at <code>https://www.ibm.com/support/pages/node/7281349</code> for specific upgrade instructions and mitigation strategies.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>prototype-pollution</category><category>nodejs</category><category>instana</category></item></channel></rss>