ServiceMonitor Component Vulnerability in Grafana Alloy
CVE-2026-75889
7.7HIGH
What is CVE-2026-75889?
The Grafana Alloy’s ServiceMonitor component presents a vulnerability enabling users with the ability to create or modify ServiceMonitor resources to specify an arbitrary local file via bearerTokenFile. The Alloy platform reads this specified file and transmits its content as a bearer token to a scrape endpoint controlled by an attacker. This may lead to the unintentional exposure of sensitive files accessible to the Alloy process, including Kubernetes service account tokens, which could potentially grant the attacker the same permissions as the Alloy service account. For exploitation to occur, the attacker must have write access to ServiceMonitor resources and possess lower privileges than the Alloy service account.
Affected Version(s)
Alloy 1.0.0 <= 1.18.1