CVE-2026-42602: CWE-208: Observable Timing Discrepancy in open-telemetry opentelemetry-collector-contrib
A vulnerability in the azureauthextension component of opentelemetry-collector-contrib versions 0.124.0 through 0.150.0 allows server-side authentication bypass. The extension improperly validates Azure access tokens by comparing them as strings without proper JWT validation and uses the client-supplied Host header to determine token scope. This flaw enables an attacker holding any valid Azure token for any scope the collector's identity can mint to authenticate to any OpenTelemetry receiver using azure_auth. Tokens remain valid for their full lifetime, typically several hours. The vulnerability has a high severity with a CVSS score of 8.1.
AI Analysis
Technical Summary
The azureauthextension in opentelemetry-collector-contrib (versions 0.124.0 to 0.150.0) contains a server-side authentication bypass vulnerability. It fails to properly validate incoming bearer tokens as JWTs, instead comparing the token string directly to a token obtained from its configured credential. The scope for the token request is taken from the client-supplied Host header, allowing tokens minted for any Azure resource accessible by the service principal to authenticate if the attacker matches the Host header. This enables token replay attacks within the token's valid lifetime. The vulnerability impacts authentication integrity and availability of OpenTelemetry receivers using azure_auth.
Potential Impact
An attacker with any valid Azure access token for any scope the collector's configured identity can mint can bypass authentication to OpenTelemetry receivers using azure_auth. This compromises authentication integrity and availability, potentially allowing unauthorized access and disruption of telemetry data collection. Tokens can be replayed for their full issued lifetime, increasing the attack window. No direct confidentiality impact is indicated. The vulnerability affects cloud-hosted services.
Mitigation Recommendations
A patch is available for this vulnerability. Since the affected product is a cloud-hosted service, the vendor typically manages remediation server-side. Users should verify with the vendor advisory that their service version is updated beyond 0.150.0 or that the patch has been applied. Until then, avoid relying on vulnerable versions. No additional mitigation steps are specified in the provided data.
CVE-2026-42602: CWE-208: Observable Timing Discrepancy in open-telemetry opentelemetry-collector-contrib
Description
A vulnerability in the azureauthextension component of opentelemetry-collector-contrib versions 0.124.0 through 0.150.0 allows server-side authentication bypass. The extension improperly validates Azure access tokens by comparing them as strings without proper JWT validation and uses the client-supplied Host header to determine token scope. This flaw enables an attacker holding any valid Azure token for any scope the collector's identity can mint to authenticate to any OpenTelemetry receiver using azure_auth. Tokens remain valid for their full lifetime, typically several hours. The vulnerability has a high severity with a CVSS score of 8.1.
CVSS v3.1
Score 8.1high
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The azureauthextension in opentelemetry-collector-contrib (versions 0.124.0 to 0.150.0) contains a server-side authentication bypass vulnerability. It fails to properly validate incoming bearer tokens as JWTs, instead comparing the token string directly to a token obtained from its configured credential. The scope for the token request is taken from the client-supplied Host header, allowing tokens minted for any Azure resource accessible by the service principal to authenticate if the attacker matches the Host header. This enables token replay attacks within the token's valid lifetime. The vulnerability impacts authentication integrity and availability of OpenTelemetry receivers using azure_auth.
Potential Impact
An attacker with any valid Azure access token for any scope the collector's configured identity can mint can bypass authentication to OpenTelemetry receivers using azure_auth. This compromises authentication integrity and availability, potentially allowing unauthorized access and disruption of telemetry data collection. Tokens can be replayed for their full issued lifetime, increasing the attack window. No direct confidentiality impact is indicated. The vulnerability affects cloud-hosted services.
Mitigation Recommendations
A patch is available for this vulnerability. Since the affected product is a cloud-hosted service, the vendor typically manages remediation server-side. Users should verify with the vendor advisory that their service version is updated beyond 0.150.0 or that the patch has been applied. Until then, avoid relying on vulnerable versions. No additional mitigation steps are specified in the provided data.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-04-29T00:31:15.725Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Is Cloud Service
- true
Threat ID: 6a04e0c9cbff5d861008114a
Added to database: 05/13/2026, 20:36:25 UTC
Last enriched: 05/21/2026, 12:24:00 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 79
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.