All verified exploits

CVE-2026-42151 Azure AD OAuth Secret Leak via Prometheus Config API

Deterministic high Prometheus Added cve-verified-cve-2026-42151

Detects Prometheus instances in versions 2.48.0 through 3.5.2 and 3.6.0 through 3.11.2 where the Azure AD remote_write OAuth client_secret field in storage/remote/azuread was declared as a plain Go string instead of the config_util.Secret alias. Prometheus only redacts fields whose declared type is Secret when serializing config to /api/v1/status/config, so the configured Azure AD client_secret is rendered in plaintext alongside the client_id and tenant_id. Any unauthenticated user who can reach Prometheus's HTTP API reads the credential in a single GET request and can mint OAuth tokens against the Azure AD app registration. Patched in 3.5.3 (LTS) and 3.11.3.

Is your app exploitable through CVE-2026-42151?

Scan your domain free