CVE-2026-42151Disclosure(prometheus / prometheus)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch prometheus prometheus systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type Secret when serving the configuration via the /-/config HTTP API endpoint. Because the field was a plain string, the Azure OAuth client secret was exposed in plaintext to any user or process with access to that endpoint. This issue has been patched in versions 3.5.3 and 3.11.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-312CWE-256

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • prometheus

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 4 mentions (2026-05-05); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
prometheus

Deep dive

Activity timeline8 mentions / 4d
01234Mentions · 2026-05-04: 2Mentions · 2026-05-05: 4Mentions · 2026-05-25: 1Mentions · 2026-06-03: 1Patch / Workaround · 2026-05-04: 1Patch / Workaround · 2026-05-05: 2Patch / Workaround · 2026-05-25: 1Technical Details · 2026-05-04: 2Technical Details · 2026-05-05: 3Technical Details · 2026-05-25: 1Technical Details · 2026-06-03: 105-0405-0505-2506-03
Signal classification2 categories
Disclosure
562.5%
Patch
337.5%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-042
Disclosure1Patch1
2026-05-054
Disclosure3Patch1
2026-05-251
Patch1
2026-06-031
Disclosure1
Full discourse8 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Prometheus secret exposure (CVE-2026-42151) A flaw in Prometheus exposed Azure OAuth client_secret in plaintext via the /-/config API due to improper handling of sensitive fields. Any user/process with access could retrieve credentials. Upgrade immediately (fixed in 3.5.3 / 3.11.3) and review access to config endpoints.

    Post summary

    The post discloses that Prometheus exposes Azure OAuth client secrets in plaintext via its /-/config API, provides a patch (v3.5.3 / v3.11.3), and urges immediate upgrade and access review.

    0101278
    121 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Prometheus Security Alert 🚨 Two high-severity vulnerabilities just dropped in Prometheus: • CVE-2026-42154 – Remote read endpoint DoS via crafted snappy payload • CVE-2026-42151 – Azure AD OAuth client secret exposure via config API Both impact http://github.com/prometheus/prometheus (Go). 👉 Potential impact: service disruption + credential leakage Patch ASAP and restrict access to remote read/config APIs.

    Post summary

    The alert announces two high‑severity CVEs in Prometheus and urges immediate patching and API restriction.

    00020137
    237 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-42151 Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAut… https://www.cve.org/CVERecord?id=CVE-2026-42151

    Post summary

    The excerpt indicates a CVE affecting Prometheus with a fixed version noted, but lacks details on exploitation or PoC and does not mention any active attacks.

    00010173
    57.4K followersView on X
  • WindowsForum@windowsforum
    Disclosure

    🪟 CVE-2026-42151 is Microsoft’s reminder that your “secure Windows” can still leak secrets via Linux containers. Plaintext OAuth in config APIs = ops nightmare, not a theory. #Windows #Microsoft #Security #AzureAD #Kubernetes #Prometheus https://windowsforum.com/threads/cve-2026-42151-prometheus-secret-leak-azure-ad-remote-write-oauth-in-plaintext.422010/?utm_source=x&utm_medium=social&utm_campaign=news_node84

    Post summary

    The post announces CVE‑2026‑42151 as a flaw that leaks secrets through plaintext OAuth configuration APIs on Windows systems running Linux containers, without mentioning PoC, exploit, or remediation details.

    0000040
    1.1K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-42151 (CVSS 7.5) - Prometheus versions <3.5.3 & <3.11.3 expose Azure AD OAuth client_secret in plaintext via /-/config API. Immediate patching required. #CVE #Vulnerability #PatchNow #ThreatIntel #DFIR https://t.co/SkSRG1gnCI

    Post summary

    Prometheus versions before 3.5.3 and 3.11.3 expose Azure AD OAuth client_secrets in plaintext via the /-/config API, necessitating immediate patching.

    0000063
    30 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Prometheus, Information Exposure, #CVE-2026-42151 (High) https://dailycve.com/prometheus-information-exposure-cve-2026-42151-high/

    Post summary

    The text announces CVE-2026-42151 as a high‑severity information exposure issue in Prometheus, without providing technical details, patches, or exploitation evidence.

    0000037
    196 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42151 Azure AD OAuth Client Secret Exposure in Prometheus Prior to 3.5.3 and 3.11.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42151

    Post summary

    New CVE disclosed that exposes Azure AD OAuth client secrets in older Prometheus versions, with technical details provided but no PoC, exploit, or patch information.

    0000047
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-42151 Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAut… https://www.cve.org/CVERecord?id=CVE-2026-42151 ----- Traducción: CVE-2026-42151 Pro… http://infoflow.cloud`

    Post summary

    The message announces CVE-2026-42151 affecting Prometheus versions 3.5.3 and 3.11.3, detailing the vulnerable field context but providing no exploitation or mitigation information.

    0000034
    75 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appprometheusprometheus---

Explore more