Grafana Alloy versions 1.0.0 through 1.18.1 are affected by CVE-2026-75889, a high-severity arbitrary local-file disclosure vulnerability (CVSS 7.7) in the prometheus.operator.servicemonitors component. An attacker able to create or modify a Kubernetes ServiceMonitor in a namespace monitored by Alloy can abuse bearerTokenFile to make Alloy read a local file and transmit its contents as a bearer token to an attacker-controlled scrape endpoint.
Files readable by the Alloy process—including its projected Kubernetes service-account token—may be exposed, potentially allowing an attacker to obtain Alloy’s Kubernetes permissions. Canadian and Guyanese cyber authorities also issued alerts for CVE-2026-19516 affecting Alloy 1.18.1 and earlier, urging administrators to review Grafana guidance and apply available updates or mitigations; the advisories did not state severity, technical impact, or active exploitation status.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security issued advisory AV26-860 for CVE-2026-19516 in Grafana Alloy, advising users and administrators to review Grafana resources and apply necessary updates when available.
Grafana Labs published CVE-2026-75889, a CVSS 7.7 high-severity arbitrary local-file disclosure flaw in Alloy's prometheus.operator.servicemonitors component. An attacker able to modify a ServiceMonitor in an Alloy-watched namespace could configure bearerTokenFile to exfiltrate files accessible to Alloy, potentially including its Kubernetes service-account token.
Grafana published a security advisory addressing CVE-2026-19516 in Grafana Alloy. The advisory identified Alloy version 1.18.1 and earlier as affected.
The Guyana National CIRT recommended that Grafana Alloy users and administrators review Grafana's CVE-2026-19516 advisory and apply necessary updates or mitigations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cirt.gy
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.