Back

HIGH

CVE-2026-75889 CVE Record

Published Aug 27, 2026

Description

Grafana Alloy’s prometheus.operator.servicemonitors component allows a user who can create or modify ServiceMonitor resources in a watched namespace to specify an arbitrary local file through bearerTokenFile. Alloy reads the file and sends its contents as a bearer token to an attacker-controlled scrape endpoint. This may disclose files accessible to the Alloy process, including its projected Kubernetes service account token, potentially granting the attacker Alloy’s Kubernetes permissions. Exploitation requires ServiceMonitor write access and lower privileges than Alloy’s service account.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GRAFANA
Published Aug 27, 2026
Updated Aug 28, 2026
Reserved Aug 18, 2026
CISA Vulnrichment
Updated Aug 28, 2026
NVD
Status Awaiting Analysis
Modified Aug 31, 2026
Red Hat
Severity n/a
Public date n/a