
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-41118 is a credential exposure vulnerability in Grafana Pyroscope, an open-source continuous profiling database, that allows unauthenticated attackers to extract the Tencent Cloud Object Storage (COS) secret_key configuration value via the Pyroscope API. The vulnerability was published on April 15, 2026, and was reported by Théo Cusnir through Grafana's bug bounty program. Affected versions include all Pyroscope releases before 1.15.2, and version 1.16.0 specifically; versions 1.15.2+, 1.16.1+, and all 1.17.x releases are patched. It carries a CVSS v3.1 base score of 9.1 (Critical) (GitHub Advisory, Grafana Advisory).
The root cause is classified as CWE-732 (Incorrect Permission Assignment for Critical Resource) and CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), meaning the Pyroscope API endpoint does not properly restrict access to sensitive configuration data (GitHub Advisory). When Pyroscope is configured to use Tencent COS as its storage backend, the secret_key credential is exposed through the API without requiring authentication, privileges, or user interaction. The attack vector is network-based with low complexity, making it trivially exploitable by any party with direct network access to the Pyroscope API (GitHub Advisory, Grafana Advisory). The sole precondition is that the Pyroscope instance must be configured to use Tencent COS as its storage backend.
Successful exploitation allows an unauthenticated attacker to retrieve the Tencent COS secret_key, which is a cloud storage credential granting access to the configured COS bucket. With this credential, an attacker could access, modify, or delete profiling data stored in the COS backend, compromising both confidentiality and integrity of stored data. There is no direct availability impact to the Pyroscope service itself, but the exposure of cloud credentials could enable broader compromise of the associated Tencent Cloud environment and any data stored therein (GitHub Advisory, Grafana Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.016% (4th percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. Despite the low exploitation probability, the unauthenticated, network-accessible nature of the flaw makes it a high-priority patching target for any internet-exposed Pyroscope instances using Tencent COS (GitHub Advisory).
secret_key along with the associated secret_id (if also obtainable) to authenticate to the Tencent Cloud COS API, enabling read, write, or delete operations on the profiling data bucket (GitHub Advisory, Grafana Advisory).secret_key from IP addresses not associated with the Pyroscope server.Grafana has released patched versions: 1.15.2 (for 1.15.x branch), 1.16.1 (for 1.16.x branch), and all 1.17.x releases include the fix. Users should upgrade to the appropriate patched version as the primary remediation. As an immediate workaround, restrict network access to the Pyroscope API using firewall rules or network policies so it is only reachable by trusted internal systems or users, and avoid exposing Pyroscope instances to the public internet. Additionally, rotating the Tencent COS secret_key is recommended for any instances that may have been exposed (GitHub Advisory, Grafana Advisory).
The vulnerability was responsibly disclosed by Théo Cusnir via Grafana's bug bounty program and acknowledged in the official Grafana security advisory. The CISA vulnerability bulletin for the week of April 13, 2026 referenced this CVE, indicating it received standard government tracking attention. Social media activity was limited, with brief mentions on Bluesky and Mastodon, and no significant community controversy or widespread media coverage was observed (Grafana Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."