Back

HIGH

OpenTelemetry Operator: ServiceMonitor bearerTokenFile reads arbitrary local file and sends contents as bearer auth

Published Sep 14, 2026

Description

The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior to 0.152.0, cmd/otel-allocator TargetAllocator instances with targetAllocator.prometheusCR.enabled set to true preserve a selected ServiceMonitor endpoint's bearerTokenFile value as HTTPClientConfig.Authorization.CredentialsFile. A tenant who can create or update a ServiceMonitor matched by serviceMonitorSelector and serviceMonitorNamespaceSelector can point bearerTokenFile at a file in the Collector pod, including /var/run/secrets/kubernetes.io/serviceaccount/token, and direct scraping to a tenant-controlled endpoint. The Collector reads that file at scrape time and sends its contents as bearer authorization on every scrape interval. Exploitation also requires the Collector service-account token or another sensitive file to be mounted and the Collector to reach the chosen target. The DenyFSAccessThroughSMs control was absent, allowing disclosure of the Collector's service-account JWT or other mounted files, and resulting Kubernetes API impact is limited by the Collector service account's permissions. This issue is fixed in version 0.152.0.

Affected products

Remediation

Red Hat statement

A flaw was found in the OpenTelemetry Operator for Kubernetes. The TargetAllocator preserves the ServiceMonitor bearerTokenFile field through to the Collector's Prometheus scrape configuration. A tenant who can create or update a ServiceMonitor can set bearerTokenFile to the Collector's mounted service account token path, causing the Collector to send its JWT to an attacker-controlled scrape target on every scrape interval. Red Hat OpenShift distributed tracing 3.10 ships a fixed version of the operator (>= 0.152.0) and is not affected.

Red Hat mitigation

Upgrade to opentelemetry-operator 0.152.0 or later, which adds DenyFSAccessThroughSMs support to drop ServiceMonitor and PodMonitor endpoints that reference arbitrary files on the file system.

References (10)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Sep 14, 2026
Updated Sep 14, 2026
Reserved May 19, 2026

CISA Vulnrichment

Updated Sep 14, 2026

NVD

Status Received
Modified Sep 14, 2026

Red Hat

Severity Important
Public date Jun 10, 2026
Bugzilla 2499680

ENISA EUVD

Assigner GitHub_M
Published Sep 14, 2026
Updated Sep 14, 2026