CVE-2026-42151

Red Hat Security Advisory: RHTAS 1.4.3 - CLI Stack Release

Description

A flaw was found in Prometheus, an open-source monitoring system. The `client_secret` field within the Azure Active Directory (AD) remote write OAuth configuration was incorrectly handled as a plain string instead of a secure Secret type. This misconfiguration allowed any user or process with access to the `/-/config` HTTP API endpoint to view the Azure OAuth client secret in plaintext. This vulnerability leads to information disclosure, potentially compromising the security of integrated Azure AD services.

Metrics

Severity
high
no public PoC known
7.5
Source: nvd-v3
28.4 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
0.4 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-08-05 18:08 UTC
CWE-200, CWE-312

Weakness classes (CWE)

  • CWE-200Class

    Exposure of Sensitive Information to an Unauthorized Actor

    The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

    cwe.mitre.org →
  • CWE-312Base

    Cleartext Storage of Sensitive Information

    The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-09-10 13:20 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/42xxx/CVE-2026-42151.json">CVE-2026-42151</a>
  2. CVE Modified2026-09-09 13:19 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/42xxx/CVE-2026-42151.json">CVE-2026-42151</a>
    • Reference: https://access.redhat.com/errata/RHSA-2026:63103
  3. CVE Modified2026-09-07 13:19 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/42xxx/CVE-2026-42151.json">CVE-2026-42151</a>
  4. CVE Modified2026-09-01 13:19 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/42xxx/CVE-2026-42151.json">CVE-2026-42151</a>
    • Reference: https://access.redhat.com/errata/RHSA-2026:60441
    • Reference: https://access.redhat.com/errata/RHSA-2026:60477
  5. CVE Modified2026-08-24 13:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 9 (+162)Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 9 (+162)

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • bitnami

    golang1.26.0-0

  • go

    golang.org/x/crypto

  • golang

    crypto0.52.0

  • golang

    go1.26.0 – 1.26.3

  • golang

    go1.25.10

  • golang

    net0.55.0

  • prometheus

    prometheus2.48.0 – 3.5.3

  • prometheus

    prometheus3.6.0 – 3.11.3

References & sources

Linked CVEs

IDCVE-2026-42151