{"api_version":"1","generated_at":"2026-07-23T11:56:21+00:00","cve":"CVE-2025-2786","urls":{"html":"https://cve.report/CVE-2025-2786","api":"https://cve.report/api/cve/CVE-2025-2786.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2025-2786","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2025-2786"},"summary":{"title":"Tempo-operator: serviceaccount token exposure leading to token and subject access reviews in openshift tempo operator","description":"A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance. This flaw allows a user with full access to their namespace to extract the ServiceAccount token and use it to submit TokenReview and SubjectAccessReview requests, potentially revealing information about other users' permissions. While this does not allow privilege escalation or impersonation, it exposes information that could aid in gathering information for further attacks.","state":"PUBLISHED","assigner":"redhat","published_at":"2025-04-02 11:15:39","updated_at":"2026-07-20 05:16:21"},"problem_types":["CWE-200","CWE-200 Exposure of Sensitive Information to an Unauthorized Actor"],"metrics":[{"version":"3.1","source":"secalert@redhat.com","type":"Secondary","score":"4.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"4.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","version":"3.1"}}],"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2354811","name":"https://bugzilla.redhat.com/show_bug.cgi?id=2354811","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/errata/RHSA-2025:3740","name":"https://access.redhat.com/errata/RHSA-2025:3740","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/security/cve/CVE-2025-2786","name":"https://access.redhat.com/security/cve/CVE-2025-2786","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/errata/RHSA-2025:3607","name":"https://access.redhat.com/errata/RHSA-2025:3607","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/grafana/tempo-operator/pull/1145","name":"https://github.com/grafana/tempo-operator/pull/1145","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-2786","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-2786","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3.5","version":"unaffected rhosdt-3.5-1743162265 * rpm","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3.5","version":"unaffected rhosdt-3.5-1744028971 * rpm","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat OpenShift distributed tracing 3","version":"","platforms":[]}],"timeline":[{"source":"CNA","time":"2025-03-25T11:13:18.903Z","lang":"en","value":"Reported to Red Hat."},{"source":"CNA","time":"2025-03-25T00:00:00.000Z","lang":"en","value":"Made public."}],"solutions":[],"workarounds":[{"source":"CNA","title":"","value":"Currently, no mitigation is available for this vulnerability.","time":"","lang":"en"}],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2025","cve_id":"2786","cve":"CVE-2025-2786","epss":"0.003360000","percentile":"0.258820000","score_date":"2026-07-20","updated_at":"2026-07-21 00:13:14"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2025-2786","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2025-04-02T13:53:24.818603Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2025-04-02T13:53:48.875Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"collectionURL":"https://github.com/grafana/tempo-operator","defaultStatus":"unaffected","packageName":"tempo-operator","versions":[{"lessThan":"0.15.3","status":"affected","version":"0","versionType":"semver"}]},{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3.5::el8"],"defaultStatus":"affected","packageName":"rhosdt/tempo-rhel8-operator","product":"Red Hat OpenShift distributed tracing 3.5","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"rhosdt-3.5-1743162265","versionType":"rpm"}]},{"collectionURL":"https://catalog.redhat.com/software/containers/","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3.5::el8"],"defaultStatus":"affected","packageName":"rhosdt/tempo-rhel8-operator","product":"Red Hat OpenShift distributed tracing 3.5","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"rhosdt-3.5-1744028971","versionType":"rpm"}]},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3"],"defaultStatus":"affected","packageName":"rhosdt/tempo-gateway-opa-rhel8","product":"Red Hat OpenShift distributed tracing 3","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3"],"defaultStatus":"affected","packageName":"rhosdt/tempo-gateway-rhel8","product":"Red Hat OpenShift distributed tracing 3","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3"],"defaultStatus":"affected","packageName":"rhosdt/tempo-jaeger-query-rhel8","product":"Red Hat OpenShift distributed tracing 3","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3"],"defaultStatus":"affected","packageName":"rhosdt/tempo-query-rhel8","product":"Red Hat OpenShift distributed tracing 3","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openshift_distributed_tracing:3"],"defaultStatus":"affected","packageName":"rhosdt/tempo-rhel8","product":"Red Hat OpenShift distributed tracing 3","vendor":"Red Hat"}],"datePublic":"2025-03-25T00:00:00.000Z","descriptions":[{"lang":"en","value":"A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance. This flaw allows a user with full access to their namespace to extract the ServiceAccount token and use it to submit TokenReview and SubjectAccessReview requests, potentially revealing information about other users' permissions. While this does not allow privilege escalation or impersonation, it exposes information that could aid in gathering information for further attacks."}],"metrics":[{"other":{"content":{"namespace":"https://access.redhat.com/security/updates/classification/","value":"Moderate"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"format":"CVSS"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-200","description":"Exposure of Sensitive Information to an Unauthorized Actor","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-07-20T04:02:13.142Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"RHSA-2025:3607","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://access.redhat.com/errata/RHSA-2025:3607"},{"name":"RHSA-2025:3740","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://access.redhat.com/errata/RHSA-2025:3740"},{"tags":["vdb-entry","x_refsource_REDHAT"],"url":"https://access.redhat.com/security/cve/CVE-2025-2786"},{"name":"RHBZ#2354811","tags":["issue-tracking","x_refsource_REDHAT"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2354811"},{"url":"https://github.com/grafana/tempo-operator/pull/1145"}],"timeline":[{"lang":"en","time":"2025-03-25T11:13:18.903Z","value":"Reported to Red Hat."},{"lang":"en","time":"2025-03-25T00:00:00.000Z","value":"Made public."}],"title":"Tempo-operator: serviceaccount token exposure leading to token and subject access reviews in openshift tempo operator","workarounds":[{"lang":"en","value":"Currently, no mitigation is available for this vulnerability."}],"x_generator":{"engine":"cvelib 1.8.0"},"x_redhatCweChain":"CWE-200: Exposure of Sensitive Information to an Unauthorized Actor"}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2025-2786","datePublished":"2025-04-02T11:07:43.285Z","dateReserved":"2025-03-25T10:51:16.783Z","dateUpdated":"2026-07-20T04:02:13.142Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2025-04-02 11:15:39","lastModifiedDate":"2026-07-20 05:16:21","problem_types":["CWE-200","CWE-200 Exposure of Sensitive Information to an Unauthorized Actor"],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-02T13:53:24.818603Z","id":"CVE-2025-2786","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2025","CveId":"2786","Ordinal":"1","Title":"Tempo-operator: serviceaccount token exposure leading to token a","CVE":"CVE-2025-2786","Year":"2025"},"notes":[{"CveYear":"2025","CveId":"2786","Ordinal":"1","NoteData":"A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance. This flaw allows a user with full access to their namespace to extract the ServiceAccount token and use it to submit TokenReview and SubjectAccessReview requests, potentially revealing information about other users' permissions. While this does not allow privilege escalation or impersonation, it exposes information that could aid in gathering information for further attacks.","Type":"Description","Title":"Tempo-operator: serviceaccount token exposure leading to token a"}]}}}