Prometheus OAuth Client Secret Exposure via /-/config (pre 3.5.3/3.11.3)
CVE-2026-42151 Published on May 4, 2026
Prometheus Azure AD remote write OAuth client secret exposed via config API
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving the configuration via the /-/config HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint. This issue has been patched in versions 3.5.3 and 3.11.3.
Vulnerability Analysis
CVE-2026-42151 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Types
What is an Information Disclosure Vulnerability?
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVE-2026-42151 has been classified to as an Information Disclosure vulnerability or weakness.
Cleartext Storage of Sensitive Information
The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere. Because the information is stored in cleartext, attackers could potentially read it. Even if the information is encoded in a way that is not human-readable, certain techniques could determine which encoding is being used, then decode the information.
Unprotected Storage of Credentials
Storing a password in plaintext may result in a system compromise. Password management issues occur when a password is stored in plaintext in an application's properties or configuration file. Storing a plaintext password in a configuration file allows anyone who can read the file access to the password-protected resource.
Products Associated with CVE-2026-42151
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-42151 are published in these products:
Affected Versions
prometheus:- Version < 3.5.3 is affected.
- Version >= 3.6.0, < 3.11.3 is affected.
- Version 0:0.152.1-1.el10_2 and below * is unaffected.
- Version 0:0.152.1-1.el10_0 and below * is unaffected.
- Version 0:0.152.1-1.el9_8 and below * is unaffected.
- Version 0:0.152.1-1.el9_4 and below * is unaffected.
- Version 0:0.152.1-1.el9_6 and below * is unaffected.
- Version 0:1.0.3-1.el9em and below * is unaffected.
- Version 0:1.1.3-1.el10em and below * is unaffected.
- Version 0:1.1.3-1.el9em and below * is unaffected.
- Version 1785418915 and below * is unaffected.
- Version 1785418855 and below * is unaffected.
- Version 1785418852 and below * is unaffected.
- Version 1784747884 and below * is unaffected.
- Version 1784747816 and below * is unaffected.
- Version 1784747815 and below * is unaffected.
- Version 1786645138 and below * is unaffected.
- Version 1786645114 and below * is unaffected.
- Version 1786645109 and below * is unaffected.
- Version 1784060681 and below * is unaffected.
- Version 1784561376 and below * is unaffected.
- Version 1784906628 and below * is unaffected.
- Version 1785442872 and below * is unaffected.
- Version 1786439449 and below * is unaffected.
- Version 1787260378 and below * is unaffected.
- Version 1787682942 and below * is unaffected.
- Version 1787681481 and below * is unaffected.
- Version 1787686252 and below * is unaffected.
- Version 1787295886 and below * is unaffected.
- Version 1787295854 and below * is unaffected.
- Version 1787261499 and below * is unaffected.
- Version 1787689380 and below * is unaffected.
- Version 1787259108 and below * is unaffected.
- Version 1787263765 and below * is unaffected.
- Version 1787263795 and below * is unaffected.
- Version 1787259314 and below * is unaffected.
- Version 1787259281 and below * is unaffected.
- Version 1787259294 and below * is unaffected.
- Version 1787263757 and below * is unaffected.
- Version 1787263834 and below * is unaffected.
- Version 1787645355 and below * is unaffected.
- Version 1786979861 and below * is unaffected.
- Version 1786976960 and below * is unaffected.
- Version 1786979923 and below * is unaffected.
- Version 1787147639 and below * is unaffected.
- Version 1787147659 and below * is unaffected.
- Version 1787147625 and below * is unaffected.
- Version 1787147638 and below * is unaffected.
- Version 1786976997 and below * is unaffected.
- Version 1787147621 and below * is unaffected.
- Version 1786979987 and below * is unaffected.
- Version 1786547818 and below * is unaffected.
- Version 1786547849 and below * is unaffected.
- Version 1786547911 and below * is unaffected.
- Version 1787238569 and below * is unaffected.
- Version 1787613736 and below * is unaffected.
- Version 1786909114 and below * is unaffected.
- Version 1786909099 and below * is unaffected.
- Version 1786908350 and below * is unaffected.
- Version 1786908427 and below * is unaffected.
- Version 1786909036 and below * is unaffected.
- Version 1787645431 and below * is unaffected.
- Version 1787222491 and below * is unaffected.
- Version 1787222490 and below * is unaffected.
- Version 1787233432 and below * is unaffected.
- Version 1787222481 and below * is unaffected.
- Version 1787316467 and below * is unaffected.
- Version 1787314818 and below * is unaffected.
- Version 1787230235 and below * is unaffected.
- Version 1787229601 and below * is unaffected.
- Version 1787324123 and below * is unaffected.
- Version 1787324110 and below * is unaffected.
- Version 1787324118 and below * is unaffected.
- Version 1787324126 and below * is unaffected.
- Version 1787229605 and below * is unaffected.
- Version 1787230287 and below * is unaffected.
- Version 1787324111 and below * is unaffected.
- Version 1787230030 and below * is unaffected.
- Version 1787229716 and below * is unaffected.
- Version 1783502022 and below * is unaffected.
- Version 1783502465 and below * is unaffected.
- Version 1783502025 and below * is unaffected.
- Version 1783502494 and below * is unaffected.
- Version 1783502401 and below * is unaffected.
- Version 1783502403 and below * is unaffected.
- Version 1783502022 and below * is unaffected.
- Version 1783502023 and below * is unaffected.
- Version 1783502029 and below * is unaffected.
- Version 1783502445 and below * is unaffected.
- Version 1784194638 and below * is unaffected.
- Version 1784194353 and below * is unaffected.
- Version 1784196588 and below * is unaffected.
- Version 1784195620 and below * is unaffected.
- Version 1784194309 and below * is unaffected.
- Version 1784194144 and below * is unaffected.
- Version 1784194188 and below * is unaffected.
- Version 1784194653 and below * is unaffected.
- Version 1784194144 and below * is unaffected.
- Version 1784194980 and below * is unaffected.
- Version 1784194347 and below * is unaffected.
- Version 1784194971 and below * is unaffected.
- Version 1784128388 and below * is unaffected.
- Version 1784128860 and below * is unaffected.
- Version 1784126780 and below * is unaffected.
- Version 1784127787 and below * is unaffected.
- Version 1784126762 and below * is unaffected.
- Version 1784127762 and below * is unaffected.
- Version 1784126832 and below * is unaffected.
- Version 1784126774 and below * is unaffected.
- Version 1784127791 and below * is unaffected.
- Version 1784127135 and below * is unaffected.
- Version 1784126733 and below * is unaffected.
- Version 1784127775 and below * is unaffected.
- Version 2.19.0-1.hum1 and below * is unaffected.
- Version 0.153.0-1.hum1 and below * is unaffected.
- Version 0.153.0-1.hum1 and below * is unaffected.
- Version 1784562060 and below * is unaffected.
- Version 1788206652 and below * is unaffected.
- Version 1787559577 and below * is unaffected.
- Version 1784125078 and below * is unaffected.
- Version 1787573491 and below * is unaffected.
- Version 1783750447 and below * is unaffected.
- Version 1783751865 and below * is unaffected.
- Version 1784353904 and below * is unaffected.
- Version 1784351966 and below * is unaffected.
- Version 1783955846 and below * is unaffected.
- Version 1784125838 and below * is unaffected.
- Version 1783968861 and below * is unaffected.
- Version 1783968861 and below * is unaffected.
- Version 1783968468 and below * is unaffected.
- Version 1783960127 and below * is unaffected.
- Version 1783968861 and below * is unaffected.
- Version 1783968861 and below * is unaffected.
- Version 4-1.4.2 and below * is unaffected.
- Version 4-1.4.3 and below * is unaffected.
- Version 1783329793 and below * is unaffected.
- Version 1785391426 and below * is unaffected.
- Version 1783329793 and below * is unaffected.
- Version 1783326748 and below * is unaffected.
- Version 1783329793 and below * is unaffected.
- Version 1783329793 and below * is unaffected.
- Version 1783329793 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.