<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T06:56:14.695328+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-grafana-2022-36062</id>
    <title>BIT-grafana-2022-36062 — Grafana folders admin only permission privilege escalation</title>
    <updated>2026-10-03T06:56:14.997336+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: grafana</p>
<p>Grafana is an open-source platform for monitoring and observability. In versions prior to 8.5.13, 9.0.9, and 9.1.6, Grafana is subject to Improper Preservation of Permissions resulting in privilege escalation on some folders where Admin is the only used permission. The vulnerability impacts Grafana instances where RBAC was disabled and enabled afterwards, as the migrations which are translating legacy folder permissions to RBAC permissions do not account for the scenario where the only user permission in the folder is Admin, as a result RBAC adds permissions for Editors and Viewers which allow them to edit and view folders accordingly. This issue has been patched in versions 8.5.13, 9.0.9, and 9.1.6. A workaround when the impacted folder/dashboard is known is to remove the additional permissions manually.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-grafana-2022-36062"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-845</id>
    <title>certfr-2022-avi-845 — De multiples vulnérabilités ont été découvertes dans Grafana. Elles
permettent à un attaquant de provoquer une élévatio…</title>
    <updated>2026-10-03T06:56:14.997424+00:00</updated>
    <content>certfr-2022-avi-845</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-845"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-266778</id>
    <title>EUVD-2026-266778</title>
    <updated>2026-10-03T06:56:14.997445+00:00</updated>
    <content>EUVD-2026-266778</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-266778"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-36062</id>
    <title>fkie_cve-2022-36062</title>
    <updated>2026-10-03T06:56:14.997458+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Grafana is an open-source platform for monitoring and observability. In versions prior to 8.5.13, 9.0.9, and 9.1.6, Grafana is subject to Improper Preservation of Permissions resulting in privilege escalation on some folders where Admin is the only used permission. The vulnerability impacts Grafana instances where RBAC was disabled and enabled afterwards, as the migrations which are translating legacy folder permissions to RBAC permissions do not account for the scenario where the only user permission in the folder is Admin, as a result RBAC adds permissions for Editors and Viewers which allow them to edit and view folders accordingly. This issue has been patched in versions 8.5.13, 9.0.9, and 9.1.6. A workaround when the impacted folder/dashboard is known is to remove the additional permissions manually.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-36062"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-p978-56hq-r492</id>
    <title>GHSA-p978-56hq-r492 — Grafana folders admin only permission privilege escalation</title>
    <updated>2026-10-03T06:56:14.997483+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/grafana/grafana</p>
<p>Today we are releasing Grafana 9.1.6, 9.0.9, 8.5.13. This patch release includes a Moderate severity security fix for CVE-2022-36062 that affects Grafana instances which are using Grafana role-based access control (RBAC).</p>
<p>Release 9.1.6, latest patch, also containing security fix:</p>
<p>- [Download Grafana 9.1.6](https://grafana.com/grafana/download/9.1.6)
- [Release notes](https://grafana.com/docs/grafana/latest/release-notes/release-notes-9-1-6/)</p>
<p>Release 9.0.9, only containing security fix:</p>
<p>- [Download Grafana 9.0.9](https://grafana.com/grafana/download/9.0.9)
- [Release notes](https://grafana.com/docs/grafana/latest/release-notes/release-notes-9-0-9/)</p>
<p>Release 8.5.13, only containing security fix:</p>
<p>- [Download Grafana 8.5.13](https://grafana.com/grafana/download/8.5.13)
- [Release notes](https://grafana.com/docs/grafana/latest/release-notes/release-notes-8-5-13/)</p>
<p>Appropriate patches have been applied to [Grafana Cloud](https://grafana.com/cloud) and as always, we closely coordinated with all cloud providers licensed to offer Grafana Pro. They have received early notification under embargo and confirmed that their offerings are secure at the time of this announcement. This is applicable to Amazon Managed Grafana and Azure's Grafana as a service offering.</p>
<p>## Privilege escalation (CVE-2022-36062)</p>
<p>### Summary</p>
<p>On August 29 we have received a bug report for Grafana role-based access control (RBAC) and confirmed a vulnerability in the Grafana. This vulnerability impacts folder…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-p978-56hq-r492"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-36062</id>
    <title>gsd-2022-36062</title>
    <updated>2026-10-03T06:56:14.997540+00:00</updated>
    <content>gsd-2022-36062</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-36062"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1186</id>
    <title>OESA-2025-1186 — grafana security update</title>
    <updated>2026-10-03T06:56:14.997553+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: grafana</p>
<p>Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB &amp;amp;amp; OpenTSDB.

Security Fix(es):</p>
<p>Grafana is an open-source platform for monitoring and observability. Versions on the 8.x and 9.x branch prior to 9.0.3, 8.5.9, 8.4.10, and 8.3.10 are vulnerable to stored cross-site scripting via the Unified Alerting feature of Grafana. An attacker can exploit this vulnerability to escalate privilege from editor to admin by tricking an authenticated admin to click on a link. Versions 9.0.3, 8.5.9, 8.4.10, and 8.3.10 contain a patch. As a workaround, it is possible to disable alerting or use legacy alerting.(CVE-2022-31097)</p>
<p>Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successfully run a malicious plugin even though unsigned plugins are not allowed. Versions 9.1.8 and 8.5.14 contain a patch for this issue. As a workaround, do not install plugins downloaded from untrusted sources.(CVE-2022-31123)</p>
<p>Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1.8 and 8.5.14 could leak authentication tokens to some destination plugins under some conditions. The vulnerability impacts data source and plugin proxy endpoints with authentication tokens. The destination plugin could receive a user&amp;apos;s Grafana…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1186"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:12366-1</id>
    <title>openSUSE-SU-2024:12366-1 — grafana-8.5.13-1.1 on GA media</title>
    <updated>2026-10-03T06:56:14.997604+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>grafana-8.5.13-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:12366-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:3676-1</id>
    <title>SUSE-SU-2022:3676-1 — Security update for grafana</title>
    <updated>2026-10-03T06:56:14.997622+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for grafana</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:3676-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-36062</id>
    <title>UBUNTU-CVE-2022-36062</title>
    <updated>2026-10-03T06:56:14.997642+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: grafana</p>
<p>Grafana is an open-source platform for monitoring and observability. In versions prior to 8.5.13, 9.0.9, and 9.1.6, Grafana is subject to Improper Preservation of Permissions resulting in privilege escalation on some folders where Admin is the only used permission. The vulnerability impacts Grafana instances where RBAC was disabled and enabled afterwards, as the migrations which are translating legacy folder permissions to RBAC permissions do not account for the scenario where the only user permission in the folder is Admin, as a result RBAC adds permissions for Editors and Viewers which allow them to edit and view folders accordingly. This issue has been patched in versions 8.5.13, 9.0.9, and 9.1.6. A workaround when the impacted folder/dashboard is known is to remove the additional permissions manually.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-36062"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1486</id>
    <title>WID-SEC-W-2022-1486 — Grafana: Mehrere Schwachstellen ermöglichen Privilegieneskalation</title>
    <updated>2026-10-03T06:56:14.997662+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Grafana ausnutzen, um seine Privilegien zu erhöhen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-1486"/>
  </entry>
</feed>
