Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
IBM strongly recommends addressing these vulnerabilities now by updating IBM Observability with Instana to the latest release as described here: https://www.ibm.com/docs/en/instana-observability?topic=agents-updating-host Affected Product(s)Version(s)Remediation/Fixes/InstructionsIBM Observability with Instana (Agent)Build 1.0.303 to 1.0.320Build 1.0.321
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7281349 |
|
Tue, 28 Jul 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable to prototype pollution through its configuration normalization API. | |
| Title | IBM Instana Observability is affected by multiple Prototype Pollution within Instana Agent container image | |
| First Time appeared |
Ibm
Ibm observability With Instana Agent |
|
| Weaknesses | CWE-1321 | |
| CPEs | cpe:2.3:a:ibm:observability_with_instana_agent:1.0.320:*:*:*:*:*:*:* cpe:2.3:a:ibm:observability_with_instana_agent:build:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm observability With Instana Agent |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-07-28T20:36:57.507Z
Reserved: 2026-07-06T18:19:15.930Z
Link: CVE-2026-14893
No data.
No data.
No data.
OpenCVE Enrichment
No data.
-
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')