CVE-2026-62147

The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was enabled, allowing an authenticated user to read span attributes belonging to other tenants' namespaces.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-13 12:16

Updated : 2026-07-13 17:01


NVD link : CVE-2026-62147

Mitre link : CVE-2026-62147

CVE.ORG link : CVE-2026-62147


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization