SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-19274

CRITICAL · CVSS 9.6 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

A vulnerability in IBM Observability with Instana allows authenticated Kubernetes tenants to hijack or permanently destroy another tenant's cluster-level RBAC permissions due to improper namespace disambiguation in cluster-scoped RBAC objects. This critical flaw can lead to unauthorized access or denial of service for cluster monitoring capabilities. Organizations utilizing Kubernetes with Instana should prioritize addressing this vulnerability to safeguard their cluster security and tenant isolation.

CVE
CVE-2026-19274
Severity
CRITICAL
CVSS
9.6
EPSS
0.21%
Kubernetes

Original NVD Description

IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scoped RBAC objects being keyed solely by the bare CR name with no namespace disambiguation, allowing a same-named `InstanaAgent` CR in an attacker-controlled namespace to silently overwrite the shared `ClusterRoleBinding` or delete it outright and revoke the victim agent's cluster monitoring access.