PT-2026-82731 · Grafana · Grafana Alloy

CVE-2026-75889

·

Published

2026-08-27

·

Updated

2026-09-02

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Grafana Alloy (affected versions not specified)
Description The prometheus.operator.servicemonitors component allows a user with permissions to create or modify ServiceMonitor resources in a watched namespace to specify an arbitrary local file using the bearerTokenFile variable. The system reads the specified file and transmits its contents as a bearer token to an external scrape endpoint controlled by an attacker. This can lead to the disclosure of files accessible to the process, such as the projected Kubernetes service account token, which may grant the attacker the Kubernetes permissions assigned to the service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Files Accessible to External Parties

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-GRAFANA-ALLOY-2026-75889
CVE-2026-75889

Affected Products

Grafana Alloy