<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T17:57:10.892124+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2023:4030</id>
    <title>ALSA-2023:4030 — Critical: grafana security update</title>
    <updated>2026-10-04T17:57:10.925836+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: grafana</p>
<p>Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB &amp; OpenTSDB.</p>
<p>Security Fix(es):</p>
<p>* grafana: account takeover possible when using Azure AD OAuth (CVE-2023-3128)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2023:4030"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2023-03343</id>
    <title>bdu:2023-03343</title>
    <updated>2026-10-04T17:57:10.925919+00:00</updated>
    <content>bdu:2023-03343</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2023-03343"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-grafana-2023-3128</id>
    <title>BIT-grafana-2023-3128</title>
    <updated>2026-10-04T17:57:10.925940+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: grafana</p>
<p>Grafana is validating Azure AD accounts based on the email claim.</p>
<p>On Azure AD, the profile email field is not unique and can be easily modified.</p>
<p>This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-grafana-2023-3128"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2023-avi-0497</id>
    <title>certfr-2023-avi-0497 — De multiples vulnérabilités ont été découvertes dans Grafana. Elles
permettent à un attaquant de provoquer un contourne…</title>
    <updated>2026-10-04T17:57:10.925965+00:00</updated>
    <content>certfr-2023-avi-0497</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2023-avi-0497"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-216449</id>
    <title>EUVD-2026-216449</title>
    <updated>2026-10-04T17:57:10.925981+00:00</updated>
    <content>EUVD-2026-216449</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-216449"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2023-3128</id>
    <title>fkie_cve-2023-3128</title>
    <updated>2026-10-04T17:57:10.925993+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Grafana is validating Azure AD accounts based on the email claim.</p>
<p>On Azure AD, the profile email field is not unique and can be easily modified.</p>
<p>This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2023-3128"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mpv3-g8m3-3fjc</id>
    <title>GHSA-mpv3-g8m3-3fjc — Grafana vulnerable to Authentication Bypass by Spoofing</title>
    <updated>2026-10-04T17:57:10.926016+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/grafana/grafana</p>
<p>Grafana is validating Azure AD accounts based on the email claim.</p>
<p>On Azure AD, the profile email field is not unique and can be easily modified.</p>
<p>This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mpv3-g8m3-3fjc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2023-3128</id>
    <title>gsd-2023-3128</title>
    <updated>2026-10-04T17:57:10.926042+00:00</updated>
    <content>gsd-2023-3128</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2023-3128"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13018-1</id>
    <title>openSUSE-SU-2024:13018-1 — grafana-10.0.1-1.1 on GA media</title>
    <updated>2026-10-04T17:57:10.926054+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>grafana-10.0.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13018-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2024:3925</id>
    <title>RHSA-2024:3925 — Red Hat Security Advisory: Red Hat Ceph Storage 7.1 security, enhancements, and bug fix update</title>
    <updated>2026-10-04T17:57:10.926072+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>grafana: account takeover possible when using Azure AD OAuth grafana: incorrect assessment of permissions across organizations go-git: Maliciously crafted Git server replies can cause DoS on go-git clients go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2024:3925"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2023:2915-1</id>
    <title>SUSE-SU-2023:2915-1 — Security update for SUSE Manager Client Tools</title>
    <updated>2026-10-04T17:57:10.926095+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for SUSE Manager Client Tools</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2023:2915-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-3128</id>
    <title>UBUNTU-CVE-2023-3128</title>
    <updated>2026-10-04T17:57:10.926111+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: grafana</p>
<p>Grafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-3128"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1551</id>
    <title>WID-SEC-W-2023-1551 — Grafana: Schwachstelle ermöglicht Übernahme von Benutzerkonto</title>
    <updated>2026-10-04T17:57:10.926130+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Grafana ausnutzen, um ein Benutzerkonto zu übernehmen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1551"/>
  </entry>
</feed>
