Kubernetes Operator Vulnerability in OpenTelemetry Collector
CVE-2026-47701

7.7HIGH

Key Information:

Vendor
CVE Published:
14 September 2026

What is CVE-2026-47701?

A vulnerability in the OpenTelemetry Operator allows attackers to exploit targetAllocator instances with enabled ServiceMonitor configurations. This can lead to the exposure of sensitive data, including the Collector's service-account JWT token. By manipulating the bearerTokenFile value, an attacker can perform unauthorized scraping of tenant-controlled endpoints. This issue is especially concerning in environments where service accounts have heightened permissions, exposing critical information if not addressed. The vulnerability is resolved in version 0.152.0 of the OpenTelemetry Operator.

Affected Version(s)

opentelemetry-operator < 0.152.0

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.