Junglewise Threat Intelligence

CVE-2026-42602: OpenTelemetry azureauthextension authentication bypass via token replay

CVE-2026-42602 · Severity: high · CVSS 8.1 · Published 2026-05-13

Vendors: Opentelemetry, Go.

Executive brief

The Azure Authenticator Extension for OpenTelemetry, which is used to secure data collection pipelines, contains a flaw that allows unauthorized users to bypass security checks. By presenting a valid Azure token intended for a different service (like Key Vault or Storage), an attacker can trick the collector into accepting unauthorized data. This could lead to the injection of fraudulent monitoring data or unauthorized access to telemetry pipelines, potentially masking malicious activity or disrupting operations.

Technical details

A vulnerability in the 'Authenticate' method of the azureauthextension (v0.124.0–v0.150.0) allows authentication bypass via token replay and scope confusion. The extension fails to perform standard JWT validation (signature, issuer, audience, or expiration checks); instead, it requests its own token for a scope derived from the client-supplied 'Host' header and performs a simple string comparison. An attacker with a valid Azure access token for any resource the collector's service principal can access (e.g., ARM, Graph, Key Vault) can authenticate by matching the 'Host' header to that resource's scope. This allows for the replay of existing tokens and the use of tokens minted for unrelated Azure services to gain access to the OpenTelemetry receiver.

Affected products

  • OpenTelemetry opentelemetry-collector-contrib/extension/azureauthextension 0.124.0 to 0.150.0

Timeline

  • 2026-04-29: advisory: GitHub Security Advisory published
  • 2026-05-13: disclosed: CVE-2026-42602 published to NVD

References

Related threats