<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T15:53:09.684464+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-grafana-2026-17183</id>
    <title>BIT-grafana-2026-17183 — CVE-2026-17183 CVE Record</title>
    <updated>2026-10-03T15:53:09.738853+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: grafana</p>
<p>An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a server-side expression while referencing a real datasource UID (incorrect authorization). This can expose data accessible through Grafana's configured datasource credentials to users who lack permission to query that datasource.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-grafana-2026-17183"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-360205</id>
    <title>EUVD-2026-360205</title>
    <updated>2026-10-03T15:53:09.738923+00:00</updated>
    <content>EUVD-2026-360205</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-360205"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-17183</id>
    <title>fkie_cve-2026-17183</title>
    <updated>2026-10-03T15:53:09.738946+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a server-side expression while referencing a real datasource UID (incorrect authorization). This can expose data accessible through Grafana's configured datasource credentials to users who lack permission to query that datasource.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-17183"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-f74r-h7qj-c63f</id>
    <title>GHSA-f74r-h7qj-c63f</title>
    <updated>2026-10-03T15:53:09.738984+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Summary</p>
<p>An authenticated organization user who can create or edit alert rules in a folder can query a datasource for which they do not have datasources:query permission. The attacker sets the client-controlled query field queryType to __expr__ while retaining the UID of a real datasource.</p>
<p>The alert-rule authorization path treats the query as a server-side expression and skips datasource permission enforcement, while the evaluator subsequently resolves and executes the query against the real datasource identified by datasourceUid.</p>
<p>## Impact</p>
<p>This bypass can expose data accessible through Grafana's configured datasource credentials to a low-privileged user who is not authorized to query that datasource directly. Confidentiality impact is High.</p>
<p>Integrity impact is Low because some datasource backends and configured credentials may permit state-changing queries. No availability impact has been demonstrated.</p>
<p>## Attack prerequisites</p>
<p>- Authenticated, low-privileged user in the same Grafana organization
- Permission to create or edit alert rules in an accessible folder
- No datasources:query permission for the targeted datasource
- Knowledge or discovery of the targeted datasource UID
- No user interaction required</p>
<p>## Technical details / root cause</p>
<p>1. The attacker submits an alert-rule query with queryType: "__expr__" and the UID of a real datasource.
2. The datasource authorization helper skips permission enforcement when query.QueryType == "__expr__".
3. queryType is clien…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-f74r-h7qj-c63f"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11684-1</id>
    <title>openSUSE-SU-2026:11684-1 — grafana-12.4.10-1.1 on GA media</title>
    <updated>2026-10-03T15:53:09.739101+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>grafana-12.4.10-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11684-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-17183</id>
    <title>UBUNTU-CVE-2026-17183</title>
    <updated>2026-10-03T15:53:09.739124+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: grafana</p>
<p>An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a server-side expression while referencing a real datasource UID (incorrect authorization). This can expose data accessible through Grafana's configured datasource credentials to users who lack permission to query that datasource.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-17183"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3355</id>
    <title>WID-SEC-W-2026-3355 — Grafana: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen und Offenlegung von Informationen</title>
    <updated>2026-10-03T15:53:09.739144+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Grafana ausnutzen, um Sicherheitsvorkehrungen zu umgehen, und um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3355"/>
  </entry>
</feed>
