Junglewise Threat Intelligence

CVE-2026-19283: IBM Instana Agent Operator etcd credential exposure via missing namespace validation

CVE-2026-19283 · Severity: high · CVSS 7.7 · Published 2026-09-04

Vendors: IBM.

Executive brief

IBM Instana Agent Operator is a Kubernetes-native component that manages agent deployment and configuration across OpenShift clusters. An authenticated attacker can exploit missing namespace validation during etcd mTLS credential copying to extract sensitive encryption certificates from the system namespace, potentially gaining unauthorized access to critical cluster data stores.

Technical details

This vulnerability is an information disclosure flaw in the IBM Instana Agent Operator's credential management logic. The operator copies etcd mTLS client certificates from the restricted openshift-etcd system namespace to user-controlled namespaces without validating the destination, allowing an authenticated attacker to inject a malicious namespace and intercept sensitive cryptographic material. The vulnerability requires authentication to the Kubernetes API but affects builds 1.0.303 through 1.0.323. An attacker with namespace creation permissions can extract the etcd client certificates needed to impersonate legitimate cluster components and access encrypted cluster state data. A fix is expected in build 1.0.324 or later.

Affected products

  • IBM Observability with Instana (Agent) 1.0.303 through 1.0.323

Timeline

  • 2026-09-04: disclosed

References

Related threats