Kubernetes Operator Vulnerability in OpenTelemetry Collector
CVE-2026-47701
7.7HIGH
What is CVE-2026-47701?
A vulnerability in the OpenTelemetry Operator allows attackers to exploit targetAllocator instances with enabled ServiceMonitor configurations. This can lead to the exposure of sensitive data, including the Collector's service-account JWT token. By manipulating the bearerTokenFile value, an attacker can perform unauthorized scraping of tenant-controlled endpoints. This issue is especially concerning in environments where service accounts have heightened permissions, exposing critical information if not addressed. The vulnerability is resolved in version 0.152.0 of the OpenTelemetry Operator.
Affected Version(s)
opentelemetry-operator < 0.152.0
