CVE-2026-42151
Microsoft · Published May 7, 2026
7.5
CVSS v3.1
HIGHPatch availableGet patch
Description
Prometheus Azure AD remote write OAuth client secret exposed via config API. Prometheus Azure AD remote write OAuth client secret exposed via config API
Affected Products
- cbl2 prometheus 2.37.9-7 on CBL Mariner 2.0
- azl3 telegraf 1.31.0-19 on Azure Linux 3.0
- azl3 telegraf 1.31.0-22 on Azure Linux 3.0
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N