SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-14893

HIGH · CVSS 7.3 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-07-28 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

The IBM Instana Node.js tracer component is susceptible to prototype pollution via its configuration normalization API, affecting versions 1.0.303 through 1.0.320. This vulnerability can lead to unauthorized manipulation of object prototypes, potentially allowing attackers to execute arbitrary code or alter application behavior. Organizations using affected versions of IBM Observability with Instana should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-14893
Severity
HIGH
CVSS
7.3
EPSS
0.20%

Original NVD Description

IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable to prototype pollution through its configuration normalization API.