CVE-2026-14893: IBM Instana Observability is affected by multiple Prototype Pollution within Instana Agent container image
IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable to prototype pollution through its configuration normalization API.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Observability with Instana (Agent)to a version that resolves this vulnerability.Fixed in Build 1.0.303 to 1.0.320 - Upgrade
Upgrade
IBM Observability with Instana (Agent)to a version that resolves this vulnerability.Fixed in Build 1.0.321 - Upgrade
Upgrade
IBM Instana Node.js tracer component @instana/coreto a version that resolves this vulnerability.Fixed in 6.2.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14893?
The severity of CVE-2026-14893 is classified as high with a CVSS score of 7.3.
How do I fix CVE-2026-14893?
To fix CVE-2026-14893, update the @instana/core package to a version that addresses the prototype pollution vulnerability.
What impact does CVE-2026-14893 have on my system?
CVE-2026-14893 can lead to potential unauthorized changes to JavaScript object prototypes, compromising the system's integrity.
Which versions of IBM Instana are affected by CVE-2026-14893?
CVE-2026-14893 affects IBM Instana Node.js tracer component @instana/core version 6.2.1 and Agent Build versions 1.0.303 through 1.0.320.
Is CVE-2026-14893 exploitable remotely?
Yes, CVE-2026-14893 is classified with an attack vector of local, meaning it is potentially exploitable remotely under certain conditions.