Information disclosure in prometheus - CVE-2026-42151

 

Information disclosure in prometheus - CVE-2026-42151

Published: April 28, 2026


Vulnerability identifier: #VU128367
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-42151
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
prometheus
Software vendor:
Prometheus

Description

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to exposure of sensitive information in the /-/config HTTP API endpoint when serving the Azure AD remote write OAuth configuration. A remote attacker can access the endpoint to disclose sensitive information.

Only deployments using Azure AD remote write with OAuth authentication are affected.


Remediation

Install security update from vendor's website.

External links