VYPR
Medium severity6.5NVD Advisory· Published Jul 13, 2026· Updated Jul 13, 2026

CVE-2026-62147

CVE-2026-62147

Description

The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was enabled, allowing an authenticated user to read span attributes belonging to other tenants' namespaces.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.