Privilege Escalation Vulnerability in Observability Operator by Red Hat
CVE-2025-2843
Key Information:
- Vendor
Rhobs
- Vendor
- CVE Published:
- 12 November 2025
What is CVE-2025-2843?
A security flaw exists in Red Hat’s Observability Operator due to the creation of a ServiceAccount with a ClusterRole during the deployment of a Namespace-Scoped Custom Resource called MonitorStack. This vulnerability can be exploited by a malicious Kubernetes account that possesses only namespace-level roles, enabling it to instantiate a MonitorStack in an authorized namespace. By doing so, the attacker may impersonate the ServiceAccount established by the Operator, leading to a significant privilege escalation and posing substantial risks to the integrity of the Kubernetes cluster.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cluster Observability Operator 1.3.1 sha256:84a281b3cd370cd42b89489c770f8b31d13e9aa570dc1b6cda6042bfba4824f8
observability-operator 0 < 1.3.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
