---
id: CVE-2025-2843
title: A flaw was found in the Observability Operator
summary: >-
  A flaw was found in the Observability Operator. The Operator creates a
  ServiceAccount with *ClusterRole* upon deployment of the *Namespace-Scoped*
  Custom Resource MonitorStack. This issue allows an adversarial Kubernetes
  Account with onl…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-266
vendor: Red Hat
product: Cluster Observability Operator 1.3.1
affected:
  - cluster_observability_operator 1.3.1
patched:
  - cluster_observability_operator 1.3.1
published: '2025-11-12'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T17:17:25.487'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-2843'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2025:21146'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2025-2843'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2355222'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-2843.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-2843'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-2843'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
  - cve.org
epss: 0.00328
epssPercentile: 0.262
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2025-11-12T20:47:54.311119Z'
ingestedAt: '2026-07-18T20:24:54.039Z'
---

## Overview

A flaw was found in the Observability Operator. The Operator creates a ServiceAccount with *ClusterRole* upon deployment of the *Namespace-Scoped* Custom Resource MonitorStack. This issue allows an adversarial Kubernetes Account with only namespaced-level roles, for example, a tenant controlling a namespace, to create a MonitorStack in the authorized namespace and then elevate permission to the cluster level by impersonating the ServiceAccount created by the Operator, resulting in privilege escalation and other issues.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2025:21146** · Red Hat · fixed in: Cluster Observability Operator 1.3.1 · released 2025-11-12 · [advisory](https://access.redhat.com/errata/RHSA-2025:21146)
