BIT-grafana-alloy-2026-75889

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/grafana-alloy/BIT-grafana-alloy-2026-75889.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-grafana-alloy-2026-75889
Aliases
  • CVE-2026-75889
Published
2026-09-02T14:40:20Z
Modified
2026-09-02T16:15:03Z
Summary
CVE-2026-75889 CVE Record
Details

Grafana Alloy’s prometheus.operator.servicemonitors component allows a user who can create or modify ServiceMonitor resources in a watched namespace to specify an arbitrary local file through bearerTokenFile. Alloy reads the file and sends its contents as a bearer token to an attacker-controlled scrape endpoint. This may disclose files accessible to the Alloy process, including its projected Kubernetes service account token, potentially granting the attacker Alloy’s Kubernetes permissions. Exploitation requires ServiceMonitor write access and lower privileges than Alloy’s service account.

Database specific
{
    "cpes":  [
        "cpe:2.3:a:grafana:alloy:*:*:*:*:*:*:*:*"
    ],
    "severity":  "High"
}
References

Affected packages

Bitnami / grafana-alloy

Package

Name
grafana-alloy
Purl
pkg:bitnami/grafana-alloy

Severity

  • 7.7 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
1.0.0
Fixed
1.19.0

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/grafana-alloy/BIT-grafana-alloy-2026-75889.json"