OpenTelemetry Operator: ServiceMonitor bearerTokenFile reads arbitrary local file and sends contents as bearer auth
Published Sep 14, 2026
7.7
HIGHCVSS 3.1
EPSS 0.46%
Description
The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior to 0.152.0, cmd/otel-allocator TargetAllocator instances with targetAllocator.prometheusCR.enabled set to true preserve a selected ServiceMonitor endpoint's bearerTokenFile value as HTTPClientConfig.Authorization.CredentialsFile. A tenant who can create or update a ServiceMonitor matched by serviceMonitorSelector and serviceMonitorNamespaceSelector can point bearerTokenFile at a file in the Collector pod, including /var/run/secrets/kubernetes.io/serviceaccount/token, and direct scraping to a tenant-controlled endpoint. The Collector reads that file at scrape time and sends its contents as bearer authorization on every scrape interval. Exploitation also requires the Collector service-account token or another sensitive file to be mounted and the Collector to reach the chosen target. The DenyFSAccessThroughSMs control was absent, allowing disclosure of the Collector's service-account JWT or other mounted files, and resulting Kubernetes API impact is limited by the Collector service account's permissions. This issue is fixed in version 0.152.0.
Affected products
-
Affected
- < 0.152.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Open-Telemetry | Opentelemetry-Operator | unknown | Affected
|
No data.
No data.
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/acm-multicluster-observability-addon-rhel9
Will not fix
Red Hat OpenShift distributed tracing 3
opentelemetry-operator
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/acm-multicluster-observability-addon-rhel9 | Will not fix | n/a |
| Red Hat OpenShift distributed tracing 3 | opentelemetry-operator | Not affected | n/a |
github.com/open-telemetry/opentelemetry-operator
Go
Introduced 0 Fixed 0.152.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/open-telemetry/opentelemetry-operator | 0 | 0.152.0 |
Remediation
Red Hat statement
A flaw was found in the OpenTelemetry Operator for Kubernetes. The TargetAllocator preserves the ServiceMonitor bearerTokenFile field through to the Collector's Prometheus scrape configuration. A tenant who can create or update a ServiceMonitor can set bearerTokenFile to the Collector's mounted service account token path, causing the Collector to send its JWT to an attacker-controlled scrape target on every scrape interval. Red Hat OpenShift distributed tracing 3.10 ships a fixed version of the operator (>= 0.152.0) and is not affected.
Red Hat mitigation
Upgrade to opentelemetry-operator 0.152.0 or later, which adds DenyFSAccessThroughSMs support to drop ServiceMonitor and PodMonitor endpoints that reference arbitrary files on the file system.
References (10)
- https://access.redhat.com/security/cve/CVE-2026-47701 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2499680 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-77578 Advisory
- https://github.com/advisories/GHSA-cxh2-4639-vmc5 Advisory
- https://github.com/open-telemetry/opentelemetry-operator/commit/95a8c2a3dc64a762d3ab8eba8c903b5702a03a9c x_refsource_MISC
- https://github.com/open-telemetry/opentelemetry-operator/pull/5104 x_refsource_MISC
- https://github.com/open-telemetry/opentelemetry-operator/releases/tag/v0.152.0 x_refsource_MISC
- https://github.com/open-telemetry/opentelemetry-operator/security/advisories/GHSA-cxh2-4639-vmc5 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-47701
- https://www.cve.org/CVERecord?id=CVE-2026-47701
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub