Privilege Escalation Vulnerability in Observability Operator by Red Hat
CVE-2025-2843
Key Information:
- Vendor
Red Hat
- Vendor
- CVE Published:
- 12 November 2025
What is CVE-2025-2843?
A security flaw exists in Red Hat’s Observability Operator due to the creation of a ServiceAccount with a ClusterRole during the deployment of a Namespace-Scoped Custom Resource called MonitorStack. This vulnerability can be exploited by a malicious Kubernetes account that possesses only namespace-level roles, enabling it to instantiate a MonitorStack in an authorized namespace. By doing so, the attacker may impersonate the ServiceAccount established by the Operator, leading to a significant privilege escalation and posing substantial risks to the integrity of the Kubernetes cluster.
Affected Version(s)
Cluster Observability Operator 1.3.0 sha256:efff0f5b6835286172ae99dd368dcc48aca98398c382cb4c38d02533afee8670
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved