PatchDay Alert

CVE

CVE-2026-42151

0field notes · 1digest CVSS 7.5


Daily digests

Prometheus exposes Azure AD OAuth client secrets through its configuration API. Anyone who can query that API endpoint can grab the secret and use it to authenticate as the Prometheus service account against Azure AD. If your Prometheus config API is reachable by untrusted users or exposed to the network, treat the affected client secrets as compromised.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.