What is CVE-2026-14893?
CVE-2026-14893 is a prototype pollution vulnerability in the IBM Instana Node.js tracer component (@instana/core version 6.2.1) via its configuration normalization API. It affects IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320. Affected systems should be updated urgently.
Azərbaycanca: CVE-2026-14893, IBM Instana Node.js tracer komponentində (@instana/core, versiya 6.2.1) configuration normalization API vasitəsilə baş verən prototype pollution zəifliyidir. Bu, IBM Observability with Instana (Agent) Build 1.0.303-1.0.320 istifadəçilərinə təsir edir. Təsirlənən sistemlərdə təcili olaraq yenilənmə aparılmalıdır.
Related CVEs
link basis: shared vendor: IBM
FAQ1
In which component of IBM Instana was CVE-2026-14893 discovered?
This critical vulnerability was discovered in the Node.js tracer component of IBM Instana, specifically in the @instana/core module (version 6.2.1). The issue stems from prototype pollution via its configuration normalization API.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.