---
title: "CVE-2026-42151\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2026-42151?format=md
keywords: index, follow
---

# CVE-2026-42151

Publication date 4 May 2026

Last updated 13 May 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**7.5 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2026-42151?format=md#impact-score)

Toggle side navigation

## Description

Prometheus is an open-source monitoring system and time series database.
Prior to versions 3.5.3 and 3.11.3, the client\_secret field in the Azure AD
remote write OAuth configuration (storage/remote/azuread) was typed as
string instead of Secret. Prometheus redacts fields of type Secret when
serving the configuration via the /-/config HTTP API endpoint. Because the
field was a plain string, the Azure OAuth client secret was exposed in
plaintext to any user or process with access to that endpoint. This issue
has been patched in versions 3.5.3 and 3.11.3.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| prometheus | 26.04 LTS resolute | Needs evaluation |
| 25.10 questing | Ignored end of life, was needs-triage |
| 24.04 LTS noble | Needs evaluation |
| 22.04 LTS jammy | Needs evaluation |
| 20.04 LTS focal | Needs evaluation |
| 18.04 LTS bionic | Needs evaluation |
| 16.04 LTS xenial | Needs evaluation |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

7.5 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | None |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.5 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42151)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-42151)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2026-42151)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2026-42151)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2026-42151>
