Description
The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior to 0.152.0, cmd/otel-allocator TargetAllocator instances with targetAllocator.prometheusCR.enabled set to true preserve a selected ServiceMonitor endpoint's bearerTokenFile value as HTTPClientConfig.Authorization.CredentialsFile. A tenant who can create or update a ServiceMonitor matched by serviceMonitorSelector and serviceMonitorNamespaceSelector can point bearerTokenFile at a file in the Collector pod, including /var/run/secrets/kubernetes.io/serviceaccount/token, and direct scraping to a tenant-controlled endpoint. The Collector reads that file at scrape time and sends its contents as bearer authorization on every scrape interval. Exploitation also requires the Collector service-account token or another sensitive file to be mounted and the Collector to reach the chosen target. The DenyFSAccessThroughSMs control was absent, allowing disclosure of the Collector's service-account JWT or other mounted files, and resulting Kubernetes API impact is limited by the Collector service account's permissions. This issue is fixed in version 0.152.0.
Published: 2026-09-14
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Exposure (service‑account token leakage)
Action: Immediate Patch
AI Analysis

Impact

The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior to version 0.152.0, TargetAllocator instances with prometheusCR.enabled set to true treat a ServiceMonitor’s bearerTokenFile field as an HTTPClientConfig.Authorization.CredentialsFile that is read during each scrape. A tenant with the ability to create or update a ServiceMonitor that matches the operator’s serviceMonitorSelector and serviceMonitorNamespaceSelector can point bearerTokenFile to any file inside the Collector pod, such as the default service‑account token at /var/run/secrets/kubernetes.io/serviceaccount/token, and have the Collector send that file’s contents as a bearer token on every scrape to a tenant‑controlled endpoint. Exploitation requires that the referenced file be mounted inside the Collector pod and that the Collector can reach the chosen target. This flaw permits disclosure of sensitive local files, including the Collector’s service‑account JWT or other mounted‑200 information‑ex.

Affected Systems

The vulnerability affects all deployments of the OpenTelemetry Operator running a version earlier than 0.152.0 when targetAllocator.prometheusCR.enabled is set to true. Any tenant who can create or update a ServiceMonitor that matches the configured serviceMonitorSelector and serviceMonitorNamespaceSelector can exploit the flaw. The issue is tied to open-telemetry:opentelemetry-operator and upgrading to 0.152.0 or later removes the vulnerability.

Risk and Exploitability

The flaw can be leveraged by an attacker with permission to create or update ServiceMonitor resources in the Kubernetes API. The attacker can point the bearerTokenFile to an arbitrary file inside the Collector pod, causing the Collector to read that file and transmit its contents as a bearer token during each scrape interval. The CVSS score is 7.7, the EPSS score is less than 1%, and the issue is not listed in the CISA KEV catalog. While the leak is limited to the permissions of the Collector’s service account, the unauthorized exposure of the service‑account JWT or other secrets poses a significant risk in multi‑tenant environments with insufficient isolation.

Generated by OpenCVE AI on September 21, 2026 at 00:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the OpenTelemetry Operator to version 0.152.0 or later to remove the vulnerability.
  • If an upgrade is not immediately possible, restrict permissions so that only trusted tenants can create or update ServiceMonitor resources matching the operator’s selectors.
  • Consider disabling targetAllocator.prometheusCR.enabled or limiting the ServiceMonitor selector to prevent unintended scraping targets.

Generated by OpenCVE AI on September 21, 2026 at 00:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-cxh2-4639-vmc5 OpenTelemetry Operator for Kubernetes's ServiceMonitor bearerTokenFile reads arbitrary local file and sends contents as bearer auth
History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior to 0.152.0, cmd/otel-allocator TargetAllocator instances with targetAllocator.prometheusCR.enabled set to true preserve a selected ServiceMonitor endpoint's bearerTokenFile value as HTTPClientConfig.Authorization.CredentialsFile. A tenant who can create or update a ServiceMonitor matched by serviceMonitorSelector and serviceMonitorNamespaceSelector can point bearerTokenFile at a file in the Collector pod, including /var/run/secrets/kubernetes.io/serviceaccount/token, and direct scraping to a tenant-controlled endpoint. The Collector reads that file at scrape time and sends its contents as bearer authorization on every scrape interval. Exploitation also requires the Collector service-account token or another sensitive file to be mounted and the Collector to reach the chosen target. The DenyFSAccessThroughSMs control was absent, allowing disclosure of the Collector's service-account JWT or other mounted files, and resulting Kubernetes API impact is limited by the Collector service account's permissions. This issue is fixed in version 0.152.0.
Title OpenTelemetry Operator: ServiceMonitor bearerTokenFile reads arbitrary local file and sends contents as bearer auth
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T16:43:18.575Z

Reserved: 2026-05-19T21:18:20.404Z

Link: CVE-2026-47701

cve-icon Vulnrichment

Updated: 2026-09-14T16:43:00.844Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T16:17:11.540

Modified: 2026-09-25T14:23:59.847

Link: CVE-2026-47701

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:45:08Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor