Executive brief
Grafana Alloy is an observability agent that collects metrics from Kubernetes clusters. An attacker with write access to ServiceMonitor resources can trick Alloy into reading arbitrary files from the system—including its Kubernetes service account token—and sending the contents to an attacker-controlled server. This could allow an attacker to escalate privileges within Kubernetes and access sensitive data.
Technical details
The vulnerability exists in the prometheus.operator.servicemonitors component of Grafana Alloy. It fails to validate the bearerTokenFile parameter in ServiceMonitor resources, allowing a user with ServiceMonitor write permissions to specify arbitrary local file paths. When Alloy processes such a ServiceMonitor, it reads the specified file and sends its contents as a bearer token to the scrape endpoint specified in the resource. An attacker can control the scrape endpoint to capture the file contents. The attack vector is network-accessible via Kubernetes ServiceMonitor resources, requiring ServiceMonitor write access but no higher privileges than Alloy itself. The fix is available in Alloy version 1.19.0 and later.
Affected products
- Grafana Alloy <1.19.0
Timeline
- 2026-08-27: disclosed
- 2026-08-27: patched: Fixed in version 1.19.0 and later