CVE-2026-14893
Received Received - Intake

Prototype Pollution in IBM Observability with Instana Agent

Vulnerability report for CVE-2026-14893, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-28

Last updated on: 2026-07-28

Assigner: IBM Corporation

Description

IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable to prototype pollution through its configuration normalization API.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-28
Last Modified
2026-07-28
Generated
2026-07-29
AI Q&A
2026-07-29
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ibm instana_node.js_tracer to 1.0.320 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1321 The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM Observability with Instana (Agent) versions 1.0.303 to 1.0.320 contain a flaw in the IBM Instana Node.js tracer component @instana/core version 6.2.1. The vulnerability allows prototype pollution through the configuration normalization API, which could let attackers modify object prototypes via crafted input.

Impact Analysis

This vulnerability could allow an attacker to manipulate object prototypes, potentially leading to unauthorized code execution, data tampering, or denial of service. It may also enable bypassing security controls or escalating privileges in affected systems.

Compliance Impact

This vulnerability could potentially lead to unauthorized data access or manipulation due to prototype pollution, which may violate GDPR's data integrity and confidentiality requirements or HIPAA's safeguards for protected health information. However, specific compliance impacts depend on deployment context and mitigations applied.

Mitigation Strategies

Update IBM Observability with Instana Agent to a version beyond 1.0.320 and ensure the Node.js tracer component @instana/core is upgraded to version 6.2.1 or higher to address the prototype pollution vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14893. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart