CVE-2026-42151

high

Description

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving the configuration via the /-/config HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint. This issue has been patched in versions 3.5.3 and 3.11.3.

References

https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42151.json

https://github.com/prometheus/prometheus/security/advisories/GHSA-wg65-39gg-5wfj

https://github.com/prometheus/prometheus/releases/tag/v3.5.3

https://github.com/prometheus/prometheus/releases/tag/v3.11.3

https://github.com/prometheus/prometheus/pull/18590

https://github.com/prometheus/prometheus/pull/18587

https://bugzilla.redhat.com/show_bug.cgi?id=2466507

https://access.redhat.com/security/cve/CVE-2026-42151

https://access.redhat.com/errata/RHSA-2026:47952

https://access.redhat.com/errata/RHSA-2026:47149

https://access.redhat.com/errata/RHSA-2026:44622

https://access.redhat.com/errata/RHSA-2026:43052

https://access.redhat.com/errata/RHSA-2026:42852

https://access.redhat.com/errata/RHSA-2026:42796

https://access.redhat.com/errata/RHSA-2026:42146

https://access.redhat.com/errata/RHSA-2026:41066

https://access.redhat.com/errata/RHSA-2026:41031

https://access.redhat.com/errata/RHSA-2026:41030

https://access.redhat.com/errata/RHSA-2026:41019

https://access.redhat.com/errata/RHSA-2026:40974

https://access.redhat.com/errata/RHSA-2026:40972

https://access.redhat.com/errata/RHSA-2026:40970

https://access.redhat.com/errata/RHSA-2026:40945

https://access.redhat.com/errata/RHSA-2026:40768

https://access.redhat.com/errata/RHSA-2026:40262

https://access.redhat.com/errata/RHSA-2026:40118

https://access.redhat.com/errata/RHSA-2026:37272

https://access.redhat.com/errata/RHSA-2026:37271

https://access.redhat.com/errata/RHSA-2026:37267

https://access.redhat.com/errata/RHSA-2026:36797

https://access.redhat.com/errata/RHSA-2026:36796

https://access.redhat.com/errata/RHSA-2026:36651

https://access.redhat.com/errata/RHSA-2026:34359

https://access.redhat.com/errata/RHSA-2026:34357

https://access.redhat.com/errata/RHSA-2026:25504

https://access.redhat.com/errata/RHSA-2026:25245

https://access.redhat.com/errata/RHSA-2026:25039

Details

Source: Mitre, NVD

Published: 2026-05-04

Updated: 2026-08-03

Risk Information

CVSS v2

Base Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

Severity: High

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity: High

EPSS

EPSS: 0.0001