← Späť na vyhľadávanie CVE

CVE-2026-42602

azureauthextension

Popis

azureauthextension is the Azure Authenticator Extension. From 0.124.0 to 0.150.0, a server-side authentication bypass in azureauthextension allows any party who holds a single valid Azure access token for any scope the collector-s configured identity can mint for to authenticate to any OpenTelemetry receiver that uses auth: azure_auth. The extension-s Authenticate method does not validate incoming bearer tokens as JWTs. Instead, it calls its own configured credential to obtain an access token and compares the client-s token to the result with string equality — and the scope for that server-side token request is taken from the client-supplied Host header. As a result, a token minted for any Azure resource the service principal has ever been issued a token for (ARM, Graph, Key Vault, Storage, etc.) will authenticate to the collector if the attacker picks a matching Host. Tokens are replayable for the full issued lifetime (commonly several hours for managed identity tokens).

CVSS 8.1EPSS 0.22200000000000003%Riziko 0.83
Zobraziť zdroj
Zverejnené
2026-05-13 21:16:47
Dotknuté verzie
>=0.124.0,<0.150.0
Typ
Core software
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H