PT-2026-7910 · Unknown+2 · Prometheus+2

Thegameprofi

·

Published

2026-02-12

·

Updated

2026-02-15

·

CVE-2026-26069

CVSS v4.0

9.1

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:L
Name of the Vulnerable Software and Affected Versions Scraparr versions 3.0.0-beta through 3.0.1
Description Scraparr, a Prometheus Exporter for the *arr Suite, disclosed Readarr API keys when the Readarr integration was enabled. This occurred because the exporter exposed the configured Readarr API key as the alias metric label value. The issue affected users if Readarr scraping was enabled with no alias configured, the exporter’s /metrics endpoint was accessible to external or unauthorized users, and the Readarr instance was externally accessible. If the /metrics endpoint was publicly accessible, the Readarr API key could be disclosed via exported metrics data. The vulnerable parameter is the alias metric label value.
Recommendations Upgrade to version 3.0.2 or later.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2026-26069
GHSA-HX24-222F-W5CJ

Affected Products

Prometheus
Readarr
Scraparr