---
id: CVE-2026-19283
title: >-
  IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM
  Instana Agent Operator could allow an authenticated remote attacker to obtain
  sensitive information, caused by missing destination namespace validation when
  copying…
summary: >-
  IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM
  Instana Agent Operator could allow an authenticated remote attacker to obtain
  sensitive information, caused by missing destination namespace validation when
  copying…
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-863
vendor: IBM
product: Observability with Instana (Agent)
affected:
  - observability_with_instana_agent >= Build 1.0.303 <= 1.0.323
published: '2026-09-04'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T21:17:24.753'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19283'
references:
  - url: 'https://www.ibm.com/support/pages/node/7286070'
    label: psirt@us.ibm.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-10T20:38:27.078421Z'
epss: 0.00307
epssPercentile: 0.20962
ingestedAt: '2026-09-08T15:33:26.961Z'
---

## Overview

IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying etcd mTLS client credentials from the openshift-etcd system namespace into an attacker-controlled namespace.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
