PT-2026-36896 · Unknown+1 · Prometheus+1

·

CVE-2026-42151

·

Published

2026-05-04

·

Updated

2026-08-27

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Prometheus versions prior to 3.5.3 Prometheus versions prior to 3.11.3
Description The client secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was incorrectly typed as a string instead of a Secret. Consequently, when the configuration is served via the '/-/config' HTTP API endpoint, the Azure OAuth client secret is exposed in plaintext to any user or process with access to that endpoint, as Prometheus only redacts fields explicitly typed as Secret.
Recommendations Update to version 3.5.3. Update to version 3.11.3.

Exploit

Fix

Cleartext Storage of Sensitive Information

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:34357
ALSA-2026:34359
AZL-86610
BIT-PROMETHEUS-2026-42151
CLEANSTART-2026-AP95632
CLEANSTART-2026-AX33738
CLEANSTART-2026-BJ92729
CLEANSTART-2026-BX78383
CLEANSTART-2026-GX27419
CLEANSTART-2026-GZ11549
CLEANSTART-2026-IE49312
CLEANSTART-2026-IT06487
CLEANSTART-2026-LC55153
CLEANSTART-2026-LY44407
CLEANSTART-2026-MJ39387
CLEANSTART-2026-MR08661
CLEANSTART-2026-MV81821
CLEANSTART-2026-NU38786
CLEANSTART-2026-OF83437
CLEANSTART-2026-PM88731
CLEANSTART-2026-QS87161
CLEANSTART-2026-SM80424
CLEANSTART-2026-TL66481
CLEANSTART-2026-TO13966
CLEANSTART-2026-UO11850
CLEANSTART-2026-XS03563
CLEANSTART-2026-ZZ38071
CVE-2026-42151
GHSA-WG65-39GG-5WFJ
GO-2026-5710
OPENSUSE-SU-2026:10676-1
OPENSUSE-SU-2026:21483-1
RHSA-2026:25039
RHSA-2026:25245
RHSA-2026:25504
RHSA-2026:34357
RHSA-2026:34359
RHSA-2026:36796
RHSA-2026:41019
RHSA-2026:53412
RHSA-2026:53413
RHSA-2026:53415
SUSE-SU-2026:2243-1
SUSE-SU-2026:2265-1
SUSE-SU-2026:2768-1
SUSE-SU-2026:2774-1

Affected Products

Prometheus
Rocky Linux