Medium severity6.5NVD Advisory· Published Jul 13, 2026· Updated Jul 13, 2026
CVE-2026-62147
CVE-2026-62147
Description
The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was enabled, allowing an authenticated user to read span attributes belonging to other tenants' namespaces.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.