PT-2026-7910 · Unknown+2 · Prometheus+2

Thegameprofi

·

Publicado

2026-02-12

·

Atualizado

2026-02-15

·

CVE-2026-26069

CVSS v4.0

9.1

Crítica

VetorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:L
Name of the Vulnerable Software and Affected Versions Scraparr versions 3.0.0-beta through 3.0.1
Description Scraparr, a Prometheus Exporter for the *arr Suite, disclosed Readarr API keys when the Readarr integration was enabled. This occurred because the exporter exposed the configured Readarr API key as the alias metric label value. The issue affected users if Readarr scraping was enabled with no alias configured, the exporter’s /metrics endpoint was accessible to external or unauthorized users, and the Readarr instance was externally accessible. If the /metrics endpoint was publicly accessible, the Readarr API key could be disclosed via exported metrics data. The vulnerable parameter is the alias metric label value.
Recommendations Upgrade to version 3.0.2 or later.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-26069
GHSA-HX24-222F-W5CJ

Produtos afetados

Prometheus
Readarr
Scraparr