Description
The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was enabled, allowing an authenticated user to read span attributes belonging to other tenants' namespaces.
Published: 2026-07-13
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Tempo Operator’s gateway component fails to apply namespace‑scoped redaction to certain query API responses when query RBAC is enabled, allowing an authenticated user to read span attributes that belong to other tenants. This authorization bypass (CWE‑863) exposes telemetry data to users who should not have access, thereby compromising tenant isolation and potentially revealing sensitive operational metrics.

Affected Systems

Red Hat OpenShift distributed tracing 3 is affected. All released versions prior to tempo‑operator v0.21.0‑2 are vulnerable; the issue is patched in that release and later versions.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity vulnerability. The EPSS score of less than 1% signals a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an authenticated user with RBAC permissions to issue query‑API requests; by sending specially crafted queries an attacker can retrieve span attributes from namespaces they are not authorized to view.

Generated by OpenCVE AI on July 31, 2026 at 11:38 UTC.

Remediation

Vendor Workaround

There is no mitigation or workaround other than upgrading to tempo-operator.v0.21.0-2 (or later); until upgraded, administrators requiring strict namespace isolation of trace data should not rely on query RBAC alone and should consider restricting access to the Tempo query API at the network/route level as a temporary compensating control.


OpenCVE Recommended Actions

  • Apply the latest tempo‑operator update (v0.21.0‑2 or later) to resolve the authorization bypass (CWE‑863).
  • If an upgrade cannot be performed immediately, restrict network or route access to the Tempo query API so that only namespaces with proper RBAC permissions can query the endpoint, mitigating the cross‑namespace read.
  • As a temporary control, disable query RBAC or enforce tighter network isolation until the patch is deployed, while monitoring for other authorization issues.

Generated by OpenCVE AI on July 31, 2026 at 11:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Description The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was enabled, allowing an authenticated user to read span attributes belonging to other tenants' namespaces.
Title Tempo-operator: tempo operator: query rbac bypass
First Time appeared Redhat
Redhat openshift Distributed Tracing
Weaknesses CWE-863
CPEs cpe:/a:redhat:openshift_distributed_tracing:3
Vendors & Products Redhat
Redhat openshift Distributed Tracing
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Redhat Openshift Distributed Tracing
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-07-13T13:43:50.023Z

Reserved: 2026-07-13T11:29:50.979Z

Link: CVE-2026-62147

cve-icon Vulnrichment

Updated: 2026-07-13T13:43:46.378Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-13T10:00:13Z

Links: CVE-2026-62147 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T11:45:13Z

Weaknesses