Information disclosure in prometheus - CVE-2026-42151
Published: April 28, 2026
prometheus
Prometheus
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to exposure of sensitive information in the /-/config HTTP API endpoint when serving the Azure AD remote write OAuth configuration. A remote attacker can access the endpoint to disclose sensitive information.
Only deployments using Azure AD remote write with OAuth authentication are affected.