{"id":"CVE-2025-2843","title":"A flaw was found in the Observability Operator","summary":"A flaw was found in the Observability Operator. The Operator creates a ServiceAccount with *ClusterRole* upon deployment of the *Namespace-Scoped* Custom Resource MonitorStack. This issue allows an adversarial Kubernetes Account with onl…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-266"],"vendor":"Red Hat","product":"Cluster Observability Operator 1.3.1","affected":["cluster_observability_operator 1.3.1"],"patched":["cluster_observability_operator 1.3.1"],"published":"2025-11-12","updated":"2026-09-21","sourceUpdated":"2026-09-21T17:17:25.487","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-2843","references":[{"url":"https://access.redhat.com/errata/RHSA-2025:21146","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2025-2843","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2355222","label":"secalert@redhat.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-2843.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-2843"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-2843"}],"tags":["nvd","csaf","vex","red-hat","cve.org"],"epss":0.00328,"epssPercentile":0.26199,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2025-11-12T20:47:54.311119Z"},"ingestedAt":"2026-07-18T20:24:54.039Z","slug":"CVE-2025-2843","body":"## Overview\n\nA flaw was found in the Observability Operator. The Operator creates a ServiceAccount with *ClusterRole* upon deployment of the *Namespace-Scoped* Custom Resource MonitorStack. This issue allows an adversarial Kubernetes Account with only namespaced-level roles, for example, a tenant controlling a namespace, to create a MonitorStack in the authorized namespace and then elevate permission to the cluster level by impersonating the ServiceAccount created by the Operator, resulting in privilege escalation and other issues.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2025:21146** · Red Hat · fixed in: Cluster Observability Operator 1.3.1 · released 2025-11-12 · [advisory](https://access.redhat.com/errata/RHSA-2025:21146)","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}