Prometheus OAuth Client Secret Exposure via /-/config (pre 3.5.3/3.11.3)
CVE-2026-42151 Published on May 4, 2026
Prometheus Azure AD remote write OAuth client secret exposed via config API
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving the configuration via the /-/config HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint. This issue has been patched in versions 3.5.3 and 3.11.3.
Vulnerability Analysis
CVE-2026-42151 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Types
What is an Information Disclosure Vulnerability?
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVE-2026-42151 has been classified to as an Information Disclosure vulnerability or weakness.
Cleartext Storage of Sensitive Information
The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere. Because the information is stored in cleartext, attackers could potentially read it. Even if the information is encoded in a way that is not human-readable, certain techniques could determine which encoding is being used, then decode the information.
Unprotected Storage of Credentials
Storing a password in plaintext may result in a system compromise. Password management issues occur when a password is stored in plaintext in an application's properties or configuration file. Storing a plaintext password in a configuration file allows anyone who can read the file access to the password-protected resource.
Products Associated with CVE-2026-42151
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-42151 are published in these products:
Affected Versions
prometheus:- Version < 3.5.3 is affected.
- Version >= 3.6.0, < 3.11.3 is affected.
- Version 0:0.152.1-1.el10_2 and below * is unaffected.
- Version 0:0.152.1-1.el9_8 and below * is unaffected.
- Version 0:1.0.3-1.el9em and below * is unaffected.
- Version 0:1.1.3-1.el10em and below * is unaffected.
- Version 0:1.1.3-1.el9em and below * is unaffected.
- Version 1784747884 and below * is unaffected.
- Version 1784747816 and below * is unaffected.
- Version 1784747815 and below * is unaffected.
- Version 1784060681 and below * is unaffected.
- Version 1784561376 and below * is unaffected.
- Version 1784906628 and below * is unaffected.
- Version 1783502022 and below * is unaffected.
- Version 1783502465 and below * is unaffected.
- Version 1783502025 and below * is unaffected.
- Version 1783502494 and below * is unaffected.
- Version 1783502401 and below * is unaffected.
- Version 1783502403 and below * is unaffected.
- Version 1783502022 and below * is unaffected.
- Version 1783502023 and below * is unaffected.
- Version 1783502029 and below * is unaffected.
- Version 1783502445 and below * is unaffected.
- Version 1784194638 and below * is unaffected.
- Version 1784194353 and below * is unaffected.
- Version 1784196588 and below * is unaffected.
- Version 1784195620 and below * is unaffected.
- Version 1784194309 and below * is unaffected.
- Version 1784194144 and below * is unaffected.
- Version 1784194188 and below * is unaffected.
- Version 1784194653 and below * is unaffected.
- Version 1784194144 and below * is unaffected.
- Version 1784194980 and below * is unaffected.
- Version 1784194347 and below * is unaffected.
- Version 1784194971 and below * is unaffected.
- Version 1784128388 and below * is unaffected.
- Version 1784128860 and below * is unaffected.
- Version 1784126780 and below * is unaffected.
- Version 1784127787 and below * is unaffected.
- Version 1784126762 and below * is unaffected.
- Version 1784127762 and below * is unaffected.
- Version 1784126832 and below * is unaffected.
- Version 1784126774 and below * is unaffected.
- Version 1784127791 and below * is unaffected.
- Version 1784127135 and below * is unaffected.
- Version 1784126733 and below * is unaffected.
- Version 1784127775 and below * is unaffected.
- Version 2.19.0-1.hum1 and below * is unaffected.
- Version 0.153.0-1.hum1 and below * is unaffected.
- Version 0.153.0-1.hum1 and below * is unaffected.
- Version 1784562060 and below * is unaffected.
- Version 1784125078 and below * is unaffected.
- Version 1783750447 and below * is unaffected.
- Version 1783751865 and below * is unaffected.
- Version 1784353904 and below * is unaffected.
- Version 1784351966 and below * is unaffected.
- Version 1783955846 and below * is unaffected.
- Version 1784125838 and below * is unaffected.
- Version 1783968861 and below * is unaffected.
- Version 1783968861 and below * is unaffected.
- Version 1783968468 and below * is unaffected.
- Version 1783960127 and below * is unaffected.
- Version 1783968861 and below * is unaffected.
- Version 1783968861 and below * is unaffected.
- Version 4-1.4.2 and below * is unaffected.
- Version 4-1.4.3 and below * is unaffected.
- Version 1783329793 and below * is unaffected.
- Version 1783329793 and below * is unaffected.
- Version 1783326748 and below * is unaffected.
- Version 1783329793 and below * is unaffected.
- Version 1783329793 and below * is unaffected.
- Version 1783329793 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.