CRITICAL 9.6 NVD

CVE-2026-19274

IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or perm

IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scoped RBAC objects being keyed solely by the bare CR name with no namespace disambiguation, allowing a same-named `InstanaAgent` CR in an attacker-controlled namespace to silently overwrite the shared `ClusterRoleBinding` or delete it outright and revoke the victim agent's cluster monitoring access.

References

Published: 2026-09-04 · Source: NVD · Feed updated: 2026-09-04
This critical severity vulnerability with a CVSS score of 9.6 was published on 2026-09-04 via NVD.

Risk Timeline

CVE Disclosed2026-09-04 · -1 days ago

Remediation Resources

vulnfeed aggregates 10236 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.