Security Advisory

CVE-2026-62147

6.5
MEDIUM

Vulnerability Description

The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was enabled, allowing an authenticated user to read span attributes belonging to other tenants' namespaces.
Published Date July 13, 2026
Official Source NIST NVD Advisory