Executive brief
IBM Instana Agent Operator is a Kubernetes-native component that manages agent deployment and configuration across OpenShift clusters. An authenticated attacker can exploit missing namespace validation during etcd mTLS credential copying to extract sensitive encryption certificates from the system namespace, potentially gaining unauthorized access to critical cluster data stores.
Technical details
This vulnerability is an information disclosure flaw in the IBM Instana Agent Operator's credential management logic. The operator copies etcd mTLS client certificates from the restricted openshift-etcd system namespace to user-controlled namespaces without validating the destination, allowing an authenticated attacker to inject a malicious namespace and intercept sensitive cryptographic material. The vulnerability requires authentication to the Kubernetes API but affects builds 1.0.303 through 1.0.323. An attacker with namespace creation permissions can extract the etcd client certificates needed to impersonate legitimate cluster components and access encrypted cluster state data. A fix is expected in build 1.0.324 or later.
Affected products
- IBM Observability with Instana (Agent) 1.0.303 through 1.0.323
Timeline
- 2026-09-04: disclosed