Security Advisory

CVE-2026-62147

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-13 11:43:59
Last updated 2026-07-13 13:43:50
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was enabled, allowing an authenticated user to read span attributes belonging to other tenants' namespaces.