Back to overview

CVE-2026-14893

HIGH
7.3
CVSS 3.1
Description
IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable to prototype pollution through its configuration normalization API.

Metadata

CVE ID
CVE-2026-14893
State
PUBLISHED
Assigner
ibm
Reserved
2026-07-06 18:19 UTC
Published
2026-07-28 20:36 UTC
Last updated
2026-07-28 20:36 UTC
Primary CWE
CWE-1321
CWE-1321 Improperly Controlled Modification of Object Protot…
Vendor / Product
IBM / Observability with Instana (Agent)
Sources
cve.org  ·  NVD

Severity & Metrics

7.3 HIGH CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
Affected products (1)
VendorProductPlatformVersions
IBM Observability with Instana (Agent) Build 1.0.303 ≤ 1.0.320
Weakness (CWE)
CWESourceDescription
CWE-1321 cna CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVSS scores (1)
ScoreSeverityVersionSourceVector
7.3 HIGH 3.1 cna CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
Back to overview