Security fixes in kube-logging-operator 6.5.2-r1 (CVE-2026-47701)
The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior to 0.152.0, cmd/otel-allocator TargetAllocator instances with targetAllocator.prometheusCR.enabled set to true preserve a selected ServiceMonitor endpoint's bearerTokenFile value as HTTPClientConfig.Authorization.CredentialsFile. A tenant who can create or update a ServiceMonitor matched by serviceMonitorSelector and serviceMonitorNamespaceSelector can point bearerTokenFile at a file in the Collector pod, including /var/run/secrets/kubernetes.io/serviceaccount/token, and direct scraping to a tenant-controlled endpoint. The Collector reads that file at scrape time and sends its contents as bearer authorization on every scrape interval. Exploitation also requires the Collector service-account token or another sensitive file to be mounted and the Collector to reach the chosen target. The DenyFSAccessThroughSMs control was absent, allowing disclosure of the Collector's service-account JWT or other mounted files, and resulting Kubernetes API impact is limited by the Collector service account's permissions. This issue is fixed in version 0.152.0.
AI Analysis
Technical Summary
The OpenTelemetry Operator for Kubernetes versions before 0.152.0 has a vulnerability where TargetAllocator instances with targetAllocator.prometheusCR.enabled set to true preserve a ServiceMonitor endpoint's bearerTokenFile as HTTPClientConfig.Authorization.CredentialsFile. A tenant able to create or update a ServiceMonitor matching specific selectors can point bearerTokenFile to sensitive files inside the Collector pod, such as the service-account token. The Collector then reads and sends this token as bearer authorization on each scrape interval. The absence of DenyFSAccessThroughSMs control allows disclosure of the Collector's service-account JWT or other mounted files. The impact on the Kubernetes API is limited by the permissions of the Collector's service account. This vulnerability is addressed in OpenTelemetry Operator version 0.152.0.
Potential Impact
An attacker with the ability to create or update certain ServiceMonitor resources can cause the OpenTelemetry Collector to disclose its service-account token or other sensitive files mounted in the Collector pod. This token could be used to access the Kubernetes API with the Collector service account's permissions, potentially leading to unauthorized actions limited by those permissions.
Mitigation Recommendations
Upgrade the OpenTelemetry Operator to version 0.152.0 or later, where this vulnerability is fixed. Since patchAvailable is true and the fix is official, applying this update remediates the issue.
Security fixes in kube-logging-operator 6.5.2-r1 (CVE-2026-47701)
Description
The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior to 0.152.0, cmd/otel-allocator TargetAllocator instances with targetAllocator.prometheusCR.enabled set to true preserve a selected ServiceMonitor endpoint's bearerTokenFile value as HTTPClientConfig.Authorization.CredentialsFile. A tenant who can create or update a ServiceMonitor matched by serviceMonitorSelector and serviceMonitorNamespaceSelector can point bearerTokenFile at a file in the Collector pod, including /var/run/secrets/kubernetes.io/serviceaccount/token, and direct scraping to a tenant-controlled endpoint. The Collector reads that file at scrape time and sends its contents as bearer authorization on every scrape interval. Exploitation also requires the Collector service-account token or another sensitive file to be mounted and the Collector to reach the chosen target. The DenyFSAccessThroughSMs control was absent, allowing disclosure of the Collector's service-account JWT or other mounted files, and resulting Kubernetes API impact is limited by the Collector service account's permissions. This issue is fixed in version 0.152.0.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The OpenTelemetry Operator for Kubernetes versions before 0.152.0 has a vulnerability where TargetAllocator instances with targetAllocator.prometheusCR.enabled set to true preserve a ServiceMonitor endpoint's bearerTokenFile as HTTPClientConfig.Authorization.CredentialsFile. A tenant able to create or update a ServiceMonitor matching specific selectors can point bearerTokenFile to sensitive files inside the Collector pod, such as the service-account token. The Collector then reads and sends this token as bearer authorization on each scrape interval. The absence of DenyFSAccessThroughSMs control allows disclosure of the Collector's service-account JWT or other mounted files. The impact on the Kubernetes API is limited by the permissions of the Collector's service account. This vulnerability is addressed in OpenTelemetry Operator version 0.152.0.
Potential Impact
An attacker with the ability to create or update certain ServiceMonitor resources can cause the OpenTelemetry Collector to disclose its service-account token or other sensitive files mounted in the Collector pod. This token could be used to access the Kubernetes API with the Collector service account's permissions, potentially leading to unauthorized actions limited by those permissions.
Mitigation Recommendations
Upgrade the OpenTelemetry Operator to version 0.152.0 or later, where this vulnerability is fixed. Since patchAvailable is true and the fix is official, applying this update remediates the issue.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- CLEANSTART-2026-TD71000
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Alpine"]
Threat ID: 6a7f442bbf8831d53962b20e
Added to database: 08/14/2026, 16:36:59 UTC
Last enriched: 09/14/2026, 22:13:42 UTC
Last updated: 09/27/2026, 03:59:29 UTC
Views: 42
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.