PT-2026-82731 · Grafana · Grafana Alloy
CVE-2026-75889
·
Published
2026-08-27
·
Updated
2026-09-02
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Grafana Alloy (affected versions not specified)
Description
The
prometheus.operator.servicemonitors component allows a user with permissions to create or modify ServiceMonitor resources in a watched namespace to specify an arbitrary local file using the bearerTokenFile variable. The system reads the specified file and transmits its contents as a bearer token to an external scrape endpoint controlled by an attacker. This can lead to the disclosure of files accessible to the process, such as the projected Kubernetes service account token, which may grant the attacker the Kubernetes permissions assigned to the service.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Grafana Alloy