Search
Find a vulnerability
Search criteria
66 vulnerabilities found for Grafana OSS by Grafana
CVE-2026-13720 (GCVE-0-2026-13720)
Vulnerability from nvd – Published: 2026-09-30 11:06 – Updated: 2026-09-30 15:28
VLAI
EPSS
VEX
Title
Editor can forge file-provisioning provenance on dashboards via the dashboard API
Summary
An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations) when creating a dashboard through the dashboard API, because these fields were stored without an authorization check. The dashboard then appears file-provisioned, and administrators can no longer update or delete it through Grafana. The impact is limited to the same organization and no data is exposed.
Severity
5.4 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 13:55 UTC
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://grafana.com/security/security-advisories/… | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Grafana | Grafana OSS |
Affected:
12.0.0 , ≤ 12.0.10
(semver)
Affected: 12.1.0 , ≤ 12.1.10 (semver) Affected: 12.2.0 , ≤ 12.2.11 (semver) Affected: 12.3.0 , ≤ 12.3.11 (semver) Affected: 12.4.0 , < 12.4.12 (semver) Affected: 13.0.0 , < 13.0.10 (semver) Affected: 13.1.0 , < 13.1.7 (semver) Affected: 13.2.0 , < 13.2.3 (semver) |
|
| Grafana | Grafana Enterprise |
Affected:
12.0.0 , ≤ 12.0.10
(semver)
Affected: 12.1.0 , ≤ 12.1.10 (semver) Affected: 12.2.0 , ≤ 12.2.11 (semver) Affected: 12.3.0 , ≤ 12.3.11 (semver) Affected: 12.4.0 , < 12.4.12 (semver) Affected: 13.0.0 , < 13.0.10 (semver) Affected: 13.1.0 , < 13.1.7 (semver) Affected: 13.2.0 , < 13.2.3 (semver) |
Date Public
2026-09-29 07:44
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-13720",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T13:55:59.494551Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T15:28:07.969Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Grafana OSS",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "12.0.10",
"status": "affected",
"version": "12.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.1.10",
"status": "affected",
"version": "12.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.2.11",
"status": "affected",
"version": "12.2.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.3.11",
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThan": "12.4.12",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThan": "13.0.10",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThan": "13.1.7",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
},
{
"lessThan": "13.2.3",
"status": "affected",
"version": "13.2.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Grafana Enterprise",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "12.0.10",
"status": "affected",
"version": "12.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.1.10",
"status": "affected",
"version": "12.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.2.11",
"status": "affected",
"version": "12.2.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.3.11",
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThan": "12.4.12",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThan": "13.0.10",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThan": "13.1.7",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
},
{
"lessThan": "13.2.3",
"status": "affected",
"version": "13.2.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "arang (Researcher)"
}
],
"datePublic": "2026-09-29T07:44:02.000Z",
"descriptions": [
{
"lang": "en",
"value": "An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations) when creating a dashboard through the dashboard API, because these fields were stored without an authorization check. The dashboard then appears file-provisioned, and administrators can no longer update or delete it through Grafana. The impact is limited to the same organization and no data is exposed."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-285",
"description": "CWE-285",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-915",
"description": "CWE-915",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-345",
"description": "CWE-345",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T11:06:38.177Z",
"orgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"shortName": "GRAFANA"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://grafana.com/security/security-advisories/cve-2026-13720"
}
],
"source": {
"discovery": "BUG_BOUNTY"
},
"title": "Editor can forge file-provisioning provenance on dashboards via the dashboard API"
}
},
"cveMetadata": {
"assignerOrgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"assignerShortName": "GRAFANA",
"cveId": "CVE-2026-13720",
"datePublished": "2026-09-30T11:06:38.177Z",
"dateReserved": "2026-06-29T14:11:02.739Z",
"dateUpdated": "2026-09-30T15:28:07.969Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-13719 (GCVE-0-2026-13719)
Vulnerability from nvd – Published: 2026-09-30 11:06 – Updated: 2026-09-30 14:29
VLAI
EPSS
VEX
Title
Alert rules in restricted folders disclosed via the alert rules list API
Summary
An authenticated user can list alert rules stored in folders they are not allowed to read through the alert rules API list endpoint. When the set of folders the user may read was empty, the folder restriction was dropped and every alert rule in the organization was returned. From Grafana 13.1.0, any user can trigger this with a folder filter. The exposed data is rule configuration; data source credentials are not exposed.
Severity
4.3 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 14:29 UTC
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://grafana.com/security/security-advisories/… | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Grafana | Grafana Enterprise |
Affected:
12.3.0 , ≤ 12.3.11
(semver)
Affected: 12.4.0 , < 12.4.12 (semver) Affected: 13.0.0 , < 13.0.10 (semver) Affected: 13.1.0 , < 13.1.7 (semver) Affected: 13.2.0 , < 13.2.3 (semver) |
|
| Grafana | Grafana OSS |
Affected:
12.3.0 , ≤ 12.3.11
(semver)
Affected: 12.4.0 , < 12.4.12 (semver) Affected: 13.0.0 , < 13.0.10 (semver) Affected: 13.1.0 , < 13.1.7 (semver) Affected: 13.2.0 , < 13.2.3 (semver) |
Date Public
2026-09-29 07:44
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-13719",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T14:29:01.284869Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T14:29:13.891Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Grafana Enterprise",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "12.3.11",
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThan": "12.4.12",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThan": "13.0.10",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThan": "13.1.7",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
},
{
"lessThan": "13.2.3",
"status": "affected",
"version": "13.2.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Grafana OSS",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "12.3.11",
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThan": "12.4.12",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThan": "13.0.10",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThan": "13.1.7",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
},
{
"lessThan": "13.2.3",
"status": "affected",
"version": "13.2.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "mon3m"
}
],
"datePublic": "2026-09-29T07:44:02.000Z",
"descriptions": [
{
"lang": "en",
"value": "An authenticated user can list alert rules stored in folders they are not allowed to read through the alert rules API list endpoint. When the set of folders the user may read was empty, the folder restriction was dropped and every alert rule in the organization was returned. From Grafana 13.1.0, any user can trigger this with a folder filter. The exposed data is rule configuration; data source credentials are not exposed."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-200",
"description": "CWE-200",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T13:05:14.113Z",
"orgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"shortName": "GRAFANA"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://grafana.com/security/security-advisories/cve-2026-13719"
}
],
"source": {
"discovery": "BUG_BOUNTY"
},
"title": "Alert rules in restricted folders disclosed via the alert rules list API"
}
},
"cveMetadata": {
"assignerOrgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"assignerShortName": "GRAFANA",
"cveId": "CVE-2026-13719",
"datePublished": "2026-09-30T11:06:38.172Z",
"dateReserved": "2026-06-29T14:10:37.534Z",
"dateUpdated": "2026-09-30T14:29:13.891Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-81842 (GCVE-0-2026-81842)
Vulnerability from nvd – Published: 2026-09-29 20:50 – Updated: 2026-09-30 15:28
VLAI
EPSS
VEX
Title
Library panel can be moved into a folder without library panel create permission
Summary
An authenticated user with edit permission on one folder can move a library panel into another folder where they only have view permission, through the library elements API or the equivalent App Platform resource. The update path did not check library panel create permission on the destination folder (incorrect authorization). No data from the destination folder is disclosed, and existing content there cannot be changed.
Severity
4.3 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 15:04 UTC
CWE
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://grafana.com/security/security-advisories/… | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Grafana | Grafana Enterprise |
Affected:
12.1.0 , ≤ 12.1.10
(semver)
Affected: 12.2.0 , ≤ 12.2.11 (semver) Affected: 12.3.0 , ≤ 12.3.11 (semver) Affected: 12.4.0 , < 12.4.12 (semver) Affected: 13.0.0 , < 13.0.10 (semver) |
|
| Grafana | Grafana OSS |
Affected:
12.1.0 , ≤ 12.1.10
(semver)
Affected: 12.2.0 , ≤ 12.2.11 (semver) Affected: 12.3.0 , ≤ 12.3.11 (semver) Affected: 12.4.0 , < 12.4.12 (semver) Affected: 13.0.0 , < 13.0.10 (semver) |
Date Public
2026-09-29 07:44
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-81842",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T15:04:07.785889Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T15:28:16.203Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Grafana Enterprise",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "12.1.10",
"status": "affected",
"version": "12.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.2.11",
"status": "affected",
"version": "12.2.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.3.11",
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThan": "12.4.12",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThan": "13.0.10",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Grafana OSS",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "12.1.10",
"status": "affected",
"version": "12.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.2.11",
"status": "affected",
"version": "12.2.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.3.11",
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThan": "12.4.12",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThan": "13.0.10",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Dohyun Choi, CIS Lab, SeoulTech"
}
],
"datePublic": "2026-09-29T07:44:02.000Z",
"descriptions": [
{
"lang": "en",
"value": "An authenticated user with edit permission on one folder can move a library panel into another folder where they only have view permission, through the library elements API or the equivalent App Platform resource. The update path did not check library panel create permission on the destination folder (incorrect authorization). No data from the destination folder is disclosed, and existing content there cannot be changed."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T13:05:14.168Z",
"orgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"shortName": "GRAFANA"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://grafana.com/security/security-advisories/cve-2026-81842"
}
],
"source": {
"discovery": "BUG_BOUNTY"
},
"title": "Library panel can be moved into a folder without library panel create permission"
}
},
"cveMetadata": {
"assignerOrgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"assignerShortName": "GRAFANA",
"cveId": "CVE-2026-81842",
"datePublished": "2026-09-29T20:50:01.257Z",
"dateReserved": "2026-08-27T15:48:54.245Z",
"dateUpdated": "2026-09-30T15:28:16.203Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-81841 (GCVE-0-2026-81841)
Vulnerability from nvd – Published: 2026-09-29 20:35 – Updated: 2026-09-30 13:05
VLAI
EPSS
VEX
Title
Paused shared dashboard access tokens still expose data source configuration
Summary
Pausing a shared (public) dashboard did not revoke its access token for the endpoints that serve frontend bootstrap data. Anyone holding the link to a paused shared dashboard could still retrieve, without authenticating, the configuration of the dashboard's data sources, including stored credentials for data sources using browser access (missing authorization). Deleting the shared dashboard does revoke the token.
Severity
5.3 (Medium)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-29 20:55 UTC
CWE
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://grafana.com/security/security-advisories/… | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Grafana | Grafana Enterprise |
Affected:
11.6.0 , ≤ 11.6.17
(semver)
Affected: 12.0.0 , ≤ 12.0.10 (semver) Affected: 12.1.0 , ≤ 12.1.10 (semver) Affected: 12.2.0 , ≤ 12.2.11 (semver) Affected: 12.3.0 , ≤ 12.3.11 (semver) Affected: 12.4.0 , < 12.4.12 (semver) Affected: 13.0.0 , < 13.0.10 (semver) Affected: 13.1.0 , < 13.1.7 (semver) Affected: 13.2.0 , < 13.2.3 (semver) |
|
| Grafana | Grafana OSS |
Affected:
11.6.0 , ≤ 11.6.17
(semver)
Affected: 12.0.0 , ≤ 12.0.10 (semver) Affected: 12.1.0 , ≤ 12.1.10 (semver) Affected: 12.2.0 , ≤ 12.2.11 (semver) Affected: 12.3.0 , ≤ 12.3.11 (semver) Affected: 12.4.0 , < 12.4.12 (semver) Affected: 13.0.0 , < 13.0.10 (semver) Affected: 13.1.0 , < 13.1.7 (semver) Affected: 13.2.0 , < 13.2.3 (semver) |
Date Public
2026-09-29 07:44
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-81841",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-29T20:55:29.746576Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T21:01:59.754Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Grafana Enterprise",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "11.6.17",
"status": "affected",
"version": "11.6.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.0.10",
"status": "affected",
"version": "12.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.1.10",
"status": "affected",
"version": "12.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.2.11",
"status": "affected",
"version": "12.2.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.3.11",
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThan": "12.4.12",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThan": "13.0.10",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThan": "13.1.7",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
},
{
"lessThan": "13.2.3",
"status": "affected",
"version": "13.2.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Grafana OSS",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "11.6.17",
"status": "affected",
"version": "11.6.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.0.10",
"status": "affected",
"version": "12.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.1.10",
"status": "affected",
"version": "12.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.2.11",
"status": "affected",
"version": "12.2.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.3.11",
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThan": "12.4.12",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThan": "13.0.10",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThan": "13.1.7",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
},
{
"lessThan": "13.2.3",
"status": "affected",
"version": "13.2.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Yeonoh Park @ CIS Lab, SeoulTech"
}
],
"datePublic": "2026-09-29T07:44:02.000Z",
"descriptions": [
{
"lang": "en",
"value": "Pausing a shared (public) dashboard did not revoke its access token for the endpoints that serve frontend bootstrap data. Anyone holding the link to a paused shared dashboard could still retrieve, without authenticating, the configuration of the dashboard\u0027s data sources, including stored credentials for data sources using browser access (missing authorization). Deleting the shared dashboard does revoke the token."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T13:05:14.107Z",
"orgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"shortName": "GRAFANA"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://grafana.com/security/security-advisories/cve-2026-81841"
}
],
"source": {
"discovery": "BUG_BOUNTY"
},
"title": "Paused shared dashboard access tokens still expose data source configuration"
}
},
"cveMetadata": {
"assignerOrgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"assignerShortName": "GRAFANA",
"cveId": "CVE-2026-81841",
"datePublished": "2026-09-29T20:35:57.152Z",
"dateReserved": "2026-08-27T15:33:30.272Z",
"dateUpdated": "2026-09-30T13:05:14.107Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76154 (GCVE-0-2026-76154)
Vulnerability from nvd – Published: 2026-09-17 20:22 – Updated: 2026-09-18 17:34
VLAI
EPSS
VEX
Title
CVE-2026-76154 CVE Record
Summary
A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user's session by hosting a malicious style configuration, enabling escalation to Org Admin.
Severity
7.3 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-18 17:33 UTC
CWE
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://grafana.com/security/security-advisories/… | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Grafana | Grafana OSS |
Affected:
12.3.0
(semver)
Affected: 12.4.0 , ≤ 12.4.10 (semver) Affected: 13.0.0 , ≤ 13.0.8 (semver) Affected: 13.1.0 , ≤ 13.1.5 (semver) Affected: 13.2.0 , ≤ 13.2.1 (semver) |
|
| Grafana | Grafana Enterprise |
Affected:
12.3.0
(semver)
Affected: 12.4.0 , ≤ 12.4.10 (semver) Affected: 13.0.0 , ≤ 13.0.8 (semver) Affected: 13.1.0 , ≤ 13.1.5 (semver) Affected: 13.2.0 , ≤ 13.2.1 (semver) |
Date Public
2026-08-19 07:45
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-76154",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-18T17:33:54.472083Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-18T17:34:10.251Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Grafana OSS",
"vendor": "Grafana",
"versions": [
{
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.4.10",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.0.8",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.1.5",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.2.1",
"status": "affected",
"version": "13.2.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Grafana Enterprise",
"vendor": "Grafana",
"versions": [
{
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.4.10",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.0.8",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.1.5",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.2.1",
"status": "affected",
"version": "13.2.0",
"versionType": "semver"
}
]
}
],
"datePublic": "2026-08-19T07:45:08.551Z",
"descriptions": [
{
"lang": "en",
"value": "A stored cross-site scripting vulnerability in the Geomap panel\u0027s MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user\u0027s session by hosting a malicious style configuration, enabling escalation to Org Admin."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T20:22:55.718Z",
"orgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"shortName": "GRAFANA"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://grafana.com/security/security-advisories/cve-2026-76154"
}
],
"source": {
"discovery": "BUG_BOUNTY"
},
"title": "CVE-2026-76154 CVE Record",
"x_generator": {
"engine": "cvelib 1.8.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"assignerShortName": "GRAFANA",
"cveId": "CVE-2026-76154",
"datePublished": "2026-09-17T20:22:55.718Z",
"dateReserved": "2026-08-19T07:45:07.588Z",
"dateUpdated": "2026-09-18T17:34:10.251Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-15815 (GCVE-0-2026-15815)
Vulnerability from nvd – Published: 2026-09-17 20:47 – Updated: 2026-09-19 03:56
VLAI
EPSS
VEX
Title
CVE-2026-15815 CVE Record
Summary
Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when
extracting plugin archives. A crafted plugin archive can chain relative symbolic link
entries to escape the plugin installation directory, writing arbitrary files and an
executable backend binary outside that directory. The dropped executable runs with the
privileges of the Grafana server process, resulting in remote code execution.
Plugin archives are extracted before their signature is verified, so a valid plugin
signature does not prevent the write. An operator can therefore be affected by
installing a plugin that appears legitimate, as well as by installing a plugin from an
arbitrary archive using grafana-cli, the GF_INSTALL_PLUGINS environment variable, or
preinstall configuration.
Grafana Enterprise is affected because it includes the same plugin extraction code as
Grafana OSS.
Severity
8.8 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-18 00:00 UTC
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://grafana.com/security/security-advisories/… | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Grafana | Grafana OSS |
Affected:
11.6.0 , ≤ 11.6.17
(semver)
Affected: 12.0.0 (semver) Affected: 12.1.0 (semver) Affected: 12.2.0 (semver) Affected: 12.3.0 (semver) Affected: 12.4.0 , ≤ 12.4.10 (semver) Affected: 13.0.0 , ≤ 13.0.8 (semver) Affected: 13.1.0 , ≤ 13.1.5 (semver) Affected: 13.2.0 , ≤ 13.2.1 (semver) |
|
| Grafana | Grafana Enterprise |
Affected:
11.6.0 , ≤ 11.6.17
(semver)
Affected: 12.0.0 (semver) Affected: 12.1.0 (semver) Affected: 12.2.0 (semver) Affected: 12.3.0 (semver) Affected: 12.4.0 , ≤ 12.4.10 (semver) Affected: 13.0.0 , ≤ 13.0.8 (semver) Affected: 13.1.0 , ≤ 13.1.5 (semver) Affected: 13.2.0 , ≤ 13.2.1 (semver) |
Date Public
2026-08-15 11:19
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-15815",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-18T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-19T03:56:26.777Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Grafana OSS",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "11.6.17",
"status": "affected",
"version": "11.6.0",
"versionType": "semver"
},
{
"status": "affected",
"version": "12.0.0",
"versionType": "semver"
},
{
"status": "affected",
"version": "12.1.0",
"versionType": "semver"
},
{
"status": "affected",
"version": "12.2.0",
"versionType": "semver"
},
{
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.4.10",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.0.8",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.1.5",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.2.1",
"status": "affected",
"version": "13.2.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Grafana Enterprise",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "11.6.17",
"status": "affected",
"version": "11.6.0",
"versionType": "semver"
},
{
"status": "affected",
"version": "12.0.0",
"versionType": "semver"
},
{
"status": "affected",
"version": "12.1.0",
"versionType": "semver"
},
{
"status": "affected",
"version": "12.2.0",
"versionType": "semver"
},
{
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.4.10",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.0.8",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.1.5",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.2.1",
"status": "affected",
"version": "13.2.0",
"versionType": "semver"
}
]
}
],
"datePublic": "2026-08-15T11:19:01.400Z",
"descriptions": [
{
"lang": "en",
"value": "Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when\nextracting plugin archives. A crafted plugin archive can chain relative symbolic link\nentries to escape the plugin installation directory, writing arbitrary files and an\nexecutable backend binary outside that directory. The dropped executable runs with the\nprivileges of the Grafana server process, resulting in remote code execution.\n\nPlugin archives are extracted before their signature is verified, so a valid plugin\nsignature does not prevent the write. An operator can therefore be affected by\ninstalling a plugin that appears legitimate, as well as by installing a plugin from an\narbitrary archive using grafana-cli, the GF_INSTALL_PLUGINS environment variable, or\npreinstall configuration.\n\nGrafana Enterprise is affected because it includes the same plugin extraction code as\nGrafana OSS."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-59",
"description": "CWE-59",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-94",
"description": "CWE-94",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T20:47:01.006Z",
"orgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"shortName": "GRAFANA"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://grafana.com/security/security-advisories/cve-2026-15815"
}
],
"source": {
"discovery": "INTERNAL_FINDING"
},
"title": "CVE-2026-15815 CVE Record",
"x_generator": {
"engine": "cvelib 1.8.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"assignerShortName": "GRAFANA",
"cveId": "CVE-2026-15815",
"datePublished": "2026-09-17T20:47:01.006Z",
"dateReserved": "2026-07-15T11:15:50.200Z",
"dateUpdated": "2026-09-19T03:56:26.777Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-19475 (GCVE-0-2026-19475)
Vulnerability from nvd – Published: 2026-09-02 15:56 – Updated: 2026-09-03 08:08
VLAI
EPSS
VEX
Title
SQL Data Source Plugin: OOM DoS via $__timeGroup macro
Summary
An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafana's regex-based macro parsing does not reject. Evaluating the injected macro causes uncontrolled memory consumption that can terminate the Grafana server process, resulting in a denial of service. The Microsoft SQL Server, PostgreSQL, and MySQL data sources are affected.
Severity
6.5 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-02 18:00 UTC
CWE
- CWE-400 - Uncontrolled Resource Consumption
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://grafana.com/security/security-advisories/… | vendor-advisory |
Impacted products
4 products
| Vendor | Product | Version | |
|---|---|---|---|
| Grafana | PostgreSQL Datasource |
Affected:
13.0.0 , ≤ 13.0.1
(semver)
|
|
| Grafana | MySQL Datasource |
Affected:
13.0.0 , ≤ 13.0.2
(semver)
|
|
| Grafana | Grafana OSS |
Affected:
11.6.0 , ≤ 11.6.16
(semver)
Affected: 12.0.0 , ≤ 12.0.10 (semver) Affected: 12.1.0 , ≤ 12.1.10 (semver) Affected: 12.2.0 , ≤ 12.2.10 (semver) Affected: 12.3.0 , ≤ 12.3.11 (semver) Affected: 12.4.0 , ≤ 12.4.9 (semver) Affected: 13.0.0 , ≤ 13.0.7 (semver) Affected: 13.1.0 , ≤ 13.1.4 (semver) |
|
| Grafana | Microsoft SQL Server Datasource |
Affected:
13.0.0 , ≤ 13.0.1
(semver)
|
Date Public
2026-09-02 09:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-19475",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-02T18:00:46.819628Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-400",
"description": "CWE-400 Uncontrolled Resource Consumption",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-02T18:01:10.582Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "PostgreSQL Datasource",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "13.0.1",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "MySQL Datasource",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "13.0.2",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Grafana OSS",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "11.6.16",
"status": "affected",
"version": "11.6.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.0.10",
"status": "affected",
"version": "12.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.1.10",
"status": "affected",
"version": "12.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.2.10",
"status": "affected",
"version": "12.2.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.3.11",
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.4.9",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.0.7",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.1.4",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Microsoft SQL Server Datasource",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "13.0.1",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "khanmarshal (Researcher)"
}
],
"datePublic": "2026-09-02T09:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafana\u0027s regex-based macro parsing does not reject. Evaluating the injected macro causes uncontrolled memory consumption that can terminate the Grafana server process, resulting in a denial of service. The Microsoft SQL Server, PostgreSQL, and MySQL data sources are affected."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-03T08:08:02.649Z",
"orgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"shortName": "GRAFANA"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://grafana.com/security/security-advisories/cve-2026-19475"
}
],
"source": {
"discovery": "BUG_BOUNTY"
},
"title": "SQL Data Source Plugin: OOM DoS via $__timeGroup macro",
"x_generator": {
"engine": "cvelib 1.8.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"assignerShortName": "GRAFANA",
"cveId": "CVE-2026-19475",
"datePublished": "2026-09-02T15:56:33.568Z",
"dateReserved": "2026-08-10T14:51:01.083Z",
"dateUpdated": "2026-09-03T08:08:02.649Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-14199 (GCVE-0-2026-14199)
Vulnerability from nvd – Published: 2026-09-02 16:06 – Updated: 2026-09-03 08:07
VLAI
EPSS
VEX
Title
Session takeover via Auth Proxy cache key collision
Summary
Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while that user's cache entry is live, is authenticated as that user, up to Administrator (authentication bypass by spoofing).
Severity
7.1 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-02 00:00 UTC
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://grafana.com/security/security-advisories/… | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Grafana | Grafana Enterprise |
Affected:
11.0.0 , ≤ 11.6.17
(semver)
Affected: 12.0.0 , ≤ 12.2.11 (semver) Affected: 12.3.0 , ≤ 12.3.11 (semver) Affected: 12.4.0 , ≤ 12.4.9 (semver) Affected: 13.0.0 , ≤ 13.0.7 (semver) Affected: 13.1.0 , ≤ 13.1.4 (semver) Affected: 13.2.0 , ≤ 13.2.0 (semver) |
|
| Grafana | Grafana OSS |
Affected:
11.0.0 , ≤ 11.6.17
(semver)
Affected: 12.0.0 , ≤ 12.2.11 (semver) Affected: 12.3.0 , ≤ 12.3.11 (semver) Affected: 12.4.0 , ≤ 12.4.9 (semver) Affected: 13.0.0 , ≤ 13.0.7 (semver) Affected: 13.1.0 , ≤ 13.1.4 (semver) Affected: 13.2.0 , ≤ 13.2.0 (semver) |
Date Public
2026-09-02 09:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-14199",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-02T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-03T03:56:40.337Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Grafana Enterprise",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "11.6.17",
"status": "affected",
"version": "11.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.2.11",
"status": "affected",
"version": "12.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.3.11",
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.4.9",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.0.7",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.1.4",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.2.0",
"status": "affected",
"version": "13.2.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Grafana OSS",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "11.6.17",
"status": "affected",
"version": "11.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.2.11",
"status": "affected",
"version": "12.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.3.11",
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.4.9",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.0.7",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.1.4",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.2.0",
"status": "affected",
"version": "13.2.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "rebelarch (Researcher)"
}
],
"datePublic": "2026-09-02T09:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user\u0027s, while that user\u0027s cache entry is live, is authenticated as that user, up to Administrator (authentication bypass by spoofing)."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-290",
"description": "CWE-290",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-1023",
"description": "CWE-1023",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-03T08:07:46.925Z",
"orgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"shortName": "GRAFANA"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://grafana.com/security/security-advisories/cve-2026-14199"
}
],
"source": {
"discovery": "BUG_BOUNTY"
},
"title": "Session takeover via Auth Proxy cache key collision",
"x_generator": {
"engine": "cvelib 1.8.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"assignerShortName": "GRAFANA",
"cveId": "CVE-2026-14199",
"datePublished": "2026-09-02T16:06:28.165Z",
"dateReserved": "2026-06-30T09:16:17.958Z",
"dateUpdated": "2026-09-03T08:07:46.925Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-19197 (GCVE-0-2026-19197)
Vulnerability from nvd – Published: 2026-08-26 08:50 – Updated: 2026-08-27 17:22
VLAI
EPSS
VEX
Title
Broken access control in dashboard snapshots
Summary
A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot's secret delete key using only its public share key (broken access control).
Severity
6.3 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-26 13:42 UTC
CWE
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://grafana.com/security/security-advisories/… | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Grafana | Grafana OSS |
Affected:
12.4.0 , < 12.4.8
(semver)
Affected: 13.0.0 , < 13.0.6 (semver) Affected: 13.1.0 , < 13.1.3 (semver) |
|
| Grafana | Grafana Enterprise |
Affected:
12.4.0 , < 12.4.8
(semver)
Affected: 13.0.0 , < 13.0.6 (semver) Affected: 13.1.0 , < 13.1.3 (semver) |
Date Public
2026-08-06 20:25
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-19197",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-26T13:42:34.663264Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-26T13:48:49.617Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Grafana OSS",
"vendor": "Grafana",
"versions": [
{
"lessThan": "12.4.8",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThan": "13.0.6",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThan": "13.1.3",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Grafana Enterprise",
"vendor": "Grafana",
"versions": [
{
"lessThan": "12.4.8",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThan": "13.0.6",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThan": "13.1.3",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Snyk"
}
],
"datePublic": "2026-08-06T20:25:59.097Z",
"descriptions": [
{
"lang": "en",
"value": "A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot\u0027s secret delete key using only its public share key (broken access control)."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T17:22:36.904Z",
"orgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"shortName": "GRAFANA"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://grafana.com/security/security-advisories/cve-2026-19197"
}
],
"source": {
"discovery": "EXTERNAL_REPORT"
},
"title": "Broken access control in dashboard snapshots",
"x_generator": {
"engine": "cvelib 1.8.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"assignerShortName": "GRAFANA",
"cveId": "CVE-2026-19197",
"datePublished": "2026-08-26T08:50:27.854Z",
"dateReserved": "2026-08-06T20:25:58.163Z",
"dateUpdated": "2026-08-27T17:22:36.904Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-17033 (GCVE-0-2026-17033)
Vulnerability from nvd – Published: 2026-08-24 13:52 – Updated: 2026-08-27 17:22
VLAI
EPSS
VEX
Title
CVE-2026-17033 CVE Record
Summary
An authenticated attacker with Editor access or alert.instances.external:write can submit an external Alertmanager alert containing a controlled generatorURL. The attacker is authorized to create the alert, but not to execute script in another user's Grafana session.
Grafana renders alert.generatorURL directly as the Alert Details See source LinkButton href without URL-scheme sanitization or a safe-protocol allowlist. The click interceptor's :// heuristic can be bypassed by placing :// inside a JavaScript comment. When a user with read access clicks See source, the browser executes attacker-controlled JavaScript in the Grafana origin with the clicking user's permissions.
Severity
6.8 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-24 15:10 UTC
CWE
- CWE-79 - IMPROPER NEUTRALIZATION OF INPUT DURING WEB PAGE GENERATION ('CROSS-SITE SCRIPTING')
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://grafana.com/security/security-advisories/… | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Grafana | Grafana OSS |
Affected:
0 , ≤ 12.3.11
(semver)
Affected: 12.4.0 , ≤ 12.4.9 (semver) Affected: 13.0.0 , ≤ 13.0.7 (semver) |
Date Public
2026-08-24 12:11
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-17033",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-24T15:10:56.482893Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-24T15:11:08.143Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Grafana OSS",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "12.3.11",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.4.9",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.0.7",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "nlgbao1340"
}
],
"datePublic": "2026-08-24T12:11:43.533Z",
"descriptions": [
{
"lang": "en",
"value": "An authenticated attacker with Editor access or alert.instances.external:write can submit an external Alertmanager alert containing a controlled generatorURL. The attacker is authorized to create the alert, but not to execute script in another user\u0027s Grafana session.\n\nGrafana renders alert.generatorURL directly as the Alert Details See source LinkButton href without URL-scheme sanitization or a safe-protocol allowlist. The click interceptor\u0027s :// heuristic can be bypassed by placing :// inside a JavaScript comment. When a user with read access clicks See source, the browser executes attacker-controlled JavaScript in the Grafana origin with the clicking user\u0027s permissions."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 6.8,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79: IMPROPER NEUTRALIZATION OF INPUT DURING WEB PAGE GENERATION (\u0027CROSS-SITE SCRIPTING\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T17:22:43.827Z",
"orgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"shortName": "GRAFANA"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://grafana.com/security/security-advisories/cve-2026-17033"
}
],
"source": {
"discovery": "BUG_BOUNTY"
},
"title": "CVE-2026-17033 CVE Record",
"x_generator": {
"engine": "cvelib 1.8.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"assignerShortName": "GRAFANA",
"cveId": "CVE-2026-17033",
"datePublished": "2026-08-24T13:52:26.910Z",
"dateReserved": "2026-07-24T12:11:43.417Z",
"dateUpdated": "2026-08-27T17:22:43.827Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-17183 (GCVE-0-2026-17183)
Vulnerability from nvd – Published: 2026-08-19 17:30 – Updated: 2026-08-27 17:22
VLAI
EPSS
VEX
Title
CVE-2026-17183 CVE Record
Summary
An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a server-side expression while referencing a real datasource UID (incorrect authorization). This can expose data accessible through Grafana's configured datasource credentials to users who lack permission to query that datasource.
Severity
7.1 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-19 18:40 UTC
CWE
- CWE-863 - INCORRECT AUTHORIZATION
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://grafana.com/security/security-advisories/… | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Grafana | Grafana OSS |
Affected:
8.4.0 , < 12.3.11
(semver)
Affected: 12.4.0 , < 12.4.9 (semver) Affected: 13.0.0 , < 13.0.7 (semver) Affected: 13.1.0 , < 13.1.4 (semver) |
|
| Grafana | Grafana Enterprise |
Affected:
8.4.0 , < 12.3.11
(semver)
Affected: 12.4.0 , < 12.4.9 (semver) Affected: 13.0.0 , < 13.0.7 (semver) Affected: 13.1.0 , < 13.1.4 (semver) |
Date Public
2026-07-24 18:38
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-17183",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-19T18:40:28.206524Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T18:42:03.891Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Grafana OSS",
"vendor": "Grafana",
"versions": [
{
"lessThan": "12.3.11",
"status": "affected",
"version": "8.4.0",
"versionType": "semver"
},
{
"lessThan": "12.4.9",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThan": "13.0.7",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThan": "13.1.4",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Grafana Enterprise",
"vendor": "Grafana",
"versions": [
{
"lessThan": "12.3.11",
"status": "affected",
"version": "8.4.0",
"versionType": "semver"
},
{
"lessThan": "12.4.9",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThan": "13.0.7",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThan": "13.1.4",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "czarflix"
}
],
"datePublic": "2026-07-24T18:38:02.945Z",
"descriptions": [
{
"lang": "en",
"value": "An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a server-side expression while referencing a real datasource UID (incorrect authorization). This can expose data accessible through Grafana\u0027s configured datasource credentials to users who lack permission to query that datasource."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863: INCORRECT AUTHORIZATION",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T17:22:31.524Z",
"orgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"shortName": "GRAFANA"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://grafana.com/security/security-advisories/cve-2026-17183"
}
],
"source": {
"discovery": "BUG_BOUNTY"
},
"title": "CVE-2026-17183 CVE Record",
"x_generator": {
"engine": "cvelib 1.8.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"assignerShortName": "GRAFANA",
"cveId": "CVE-2026-17183",
"datePublished": "2026-08-19T17:30:06.798Z",
"dateReserved": "2026-07-24T18:38:02.221Z",
"dateUpdated": "2026-08-27T17:22:31.524Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-11817 (GCVE-0-2026-11817)
Vulnerability from nvd – Published: 2026-08-17 21:28 – Updated: 2026-09-14 10:16
VLAI
EPSS
VEX
Title
CVE-2026-11817 CVE Record
Summary
This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted. In a multi-organization stack, a user who is an Org Admin of a single organization can call GET /api/access-control/users/permissions/search?actionPrefix=dashboards: and receive permission data belonging to other organizations. The disclosed data is limited to dashboard and folder identifiers (UIDs) and per-user permission/scope mappings (which user holds which access on which dashboard). Dashboard contents, panels, query results, datasource credentials, secrets, and personal data are not exposed. This is a limited cross-organization information disclosure affecting multi-org deployments only.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-18 15:22 UTC
CWE
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://grafana.com/security/security-advisories/… | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Grafana | Grafana OSS |
Affected:
12.4.0 , ≤ 12.4.5
(semver)
Affected: 11.2.0 , ≤ 11.6.16 (semver) Affected: 13.0.0 , ≤ 13.0.3 (semver) Affected: 13.1.0 , ≤ 13.1.0 (semver) Affected: 12.2.0 , ≤ 12.2.10 (semver) Affected: 12.3.0 , ≤ 12.3.8 (semver) |
|
| Grafana | Grafana Enterprise |
Affected:
13.0.0 , ≤ 13.0.3
(semver)
Affected: 12.2.0 , ≤ 12.2.10 (semver) Affected: 11.2.0 , ≤ 11.6.16 (semver) Affected: 12.3.0 , ≤ 12.3.8 (semver) Affected: 12.4.0 , ≤ 12.4.5 (semver) Affected: 13.1.0 , ≤ 13.1.0 (semver) |
Date Public
2026-07-17 14:01
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-11817",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-18T15:22:39.226844Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-18T15:22:45.428Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Grafana OSS",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "12.4.5",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "11.6.16",
"status": "affected",
"version": "11.2.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.0.3",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.1.0",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.2.10",
"status": "affected",
"version": "12.2.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.3.8",
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Grafana Enterprise",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "13.0.3",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.2.10",
"status": "affected",
"version": "12.2.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "11.6.16",
"status": "affected",
"version": "11.2.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.3.8",
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.4.5",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.1.0",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Harish Kolla"
}
],
"datePublic": "2026-07-17T14:01:45.422Z",
"descriptions": [
{
"lang": "en",
"value": "This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted. In a multi-organization stack, a user who is an Org Admin of a single organization can call GET /api/access-control/users/permissions/search?actionPrefix=dashboards: and receive permission data belonging to other organizations. The disclosed data is limited to dashboard and folder identifiers (UIDs) and per-user permission/scope mappings (which user holds which access on which dashboard). Dashboard contents, panels, query results, datasource credentials, secrets, and personal data are not exposed. This is a limited cross-organization information disclosure affecting multi-org deployments only."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-14T10:16:35.588Z",
"orgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"shortName": "GRAFANA"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://grafana.com/security/security-advisories/cve-2026-11817"
}
],
"source": {
"discovery": "BUG_BOUNTY"
},
"title": "CVE-2026-11817 CVE Record",
"x_generator": {
"engine": "cvelib 1.8.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"assignerShortName": "GRAFANA",
"cveId": "CVE-2026-11817",
"datePublished": "2026-08-17T21:28:17.497Z",
"dateReserved": "2026-06-09T16:24:38.153Z",
"dateUpdated": "2026-09-14T10:16:35.588Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-21723 (GCVE-0-2026-21723)
Vulnerability from nvd – Published: 2026-07-23 01:48 – Updated: 2026-08-27 17:22
VLAI
EPSS
VEX
Title
CVE-2026-21723 Record
Summary
The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anonymous access enabled.
Severity
5.3 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-07-23 14:15 UTC
CWE
- CWE-400 - Uncontrolled Resource Consumption
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://grafana.com/security/security-advisories/… | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Grafana | Grafana OSS |
Affected:
8.0.0 , ≤ 11.0.0
(semver)
Affected: 11.0.0 , ≤ 11.6.10 (semver) Affected: 12.0.0 , ≤ 12.0.9 (semver) Affected: 12.1.0 , ≤ 12.1.6 (semver) Affected: 12.2.0 , ≤ 12.2.4 (semver) Affected: 12.3.0 , ≤ 12.3.2 (semver) |
Date Public
2026-07-22 01:42
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-21723",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-23T14:15:50.650728Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-400",
"description": "CWE-400 Uncontrolled Resource Consumption",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-23T14:16:10.097Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Grafana OSS",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "11.0.0",
"status": "affected",
"version": "8.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "11.6.10",
"status": "affected",
"version": "11.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.0.9",
"status": "affected",
"version": "12.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.1.6",
"status": "affected",
"version": "12.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.2.4",
"status": "affected",
"version": "12.2.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.3.2",
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "nacl (Researcher)"
}
],
"datePublic": "2026-07-22T01:42:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anonymous access enabled."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T17:22:29.672Z",
"orgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"shortName": "GRAFANA"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://grafana.com/security/security-advisories/cve-2026-21723"
}
],
"source": {
"discovery": "BUG_BOUNTY"
},
"title": "CVE-2026-21723 Record",
"x_generator": {
"engine": "cvelib 1.8.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"assignerShortName": "GRAFANA",
"cveId": "CVE-2026-21723",
"datePublished": "2026-07-23T01:48:16.245Z",
"dateReserved": "2026-01-05T09:26:06.214Z",
"dateUpdated": "2026-08-27T17:22:29.672Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-8609 (GCVE-0-2026-8609)
Vulnerability from nvd – Published: 2026-07-10 14:58 – Updated: 2026-08-27 17:22
VLAI
EPSS
VEX
Title
Pre-authentication denial of service via the OAuth login route
Summary
An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).
Severity
5.3 (Medium)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-07-10 15:53 UTC
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://grafana.com/security/security-advisories/… | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Grafana | Grafana OSS |
Affected:
11.6.0 , ≤ 11.6.14
(semver)
Affected: 12.2.0 , ≤ 12.2.8 (semver) Affected: 12.3.0 , ≤ 12.3.6 (semver) Affected: 12.4.0 , ≤ 12.4.3 (semver) Affected: 13.0.0 , ≤ 13.0.1 (semver) |
Date Public
2026-06-09 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-8609",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-10T15:53:40.169487Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-400",
"description": "CWE-400 Uncontrolled Resource Consumption",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-10T15:53:51.365Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Grafana OSS",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "11.6.14",
"status": "affected",
"version": "11.6.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.2.8",
"status": "affected",
"version": "12.2.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.3.6",
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.4.3",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.0.1",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "cyberjoker (Researcher)"
}
],
"datePublic": "2026-06-09T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "An unauthenticated attacker can repeatedly call Grafana\u0027s OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service)."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-400",
"description": "CWE-400",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T17:22:37.575Z",
"orgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"shortName": "GRAFANA"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://grafana.com/security/security-advisories/cve-2026-8609"
}
],
"source": {
"discovery": "BUG_BOUNTY"
},
"title": "Pre-authentication denial of service via the OAuth login route",
"x_generator": {
"engine": "cvelib 1.8.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"assignerShortName": "GRAFANA",
"cveId": "CVE-2026-8609",
"datePublished": "2026-07-10T14:58:33.522Z",
"dateReserved": "2026-05-14T16:01:42.297Z",
"dateUpdated": "2026-08-27T17:22:37.575Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-8595 (GCVE-0-2026-8595)
Vulnerability from nvd – Published: 2026-07-10 14:59 – Updated: 2026-08-27 17:22
VLAI
EPSS
VEX
Title
Stored XSS in the table panel (TableNG)
Summary
A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting).
Severity
6.8 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-07-10 15:59 UTC
CWE
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://grafana.com/security/security-advisories/… | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Grafana | Grafana OSS |
Affected:
12.4.0 , ≤ 12.4.3
(semver)
Affected: 13.0.0 , ≤ 13.0.1 (semver) |
Date Public
2026-06-09 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-8595",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-10T15:59:08.422134Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-10T15:59:19.628Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Grafana OSS",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "12.4.3",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.0.1",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "avamost369 (Researcher)"
}
],
"datePublic": "2026-06-09T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting)."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 6.8,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T17:22:45.998Z",
"orgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"shortName": "GRAFANA"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://grafana.com/security/security-advisories/cve-2026-8595"
}
],
"source": {
"discovery": "BUG_BOUNTY"
},
"title": "Stored XSS in the table panel (TableNG)",
"x_generator": {
"engine": "cvelib 1.8.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"assignerShortName": "GRAFANA",
"cveId": "CVE-2026-8595",
"datePublished": "2026-07-10T14:59:35.891Z",
"dateReserved": "2026-05-14T12:50:43.291Z",
"dateUpdated": "2026-08-27T17:22:45.998Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-33382 (GCVE-0-2026-33382)
Vulnerability from nvd – Published: 2026-07-10 14:58 – Updated: 2026-08-27 17:22
VLAI
EPSS
VEX
Title
Denial of service via unbounded request body size
Summary
Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.
Severity
7.5 (High)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-07-10 15:59 UTC
CWE
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://grafana.com/security/security-advisories/… | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Grafana | Grafana OSS |
Affected:
11.6.0 , ≤ 11.6.14
(semver)
Affected: 12.2.0 , ≤ 12.2.8 (semver) Affected: 12.3.0 , ≤ 12.3.6 (semver) Affected: 12.4.0 , ≤ 12.4.3 (semver) Affected: 13.0.0 , ≤ 13.0.1 (semver) |
Date Public
2026-06-09 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-33382",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-10T15:59:38.846803Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-07-10T15:59:43.742Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Grafana OSS",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "11.6.14",
"status": "affected",
"version": "11.6.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.2.8",
"status": "affected",
"version": "12.2.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.3.6",
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.4.3",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.0.1",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
}
]
}
],
"datePublic": "2026-06-09T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-400",
"description": "CWE-400",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T17:22:28.355Z",
"orgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"shortName": "GRAFANA"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://grafana.com/security/security-advisories/cve-2026-33382"
}
],
"source": {
"discovery": "INTERNAL_FINDING"
},
"title": "Denial of service via unbounded request body size",
"x_generator": {
"engine": "cvelib 1.8.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"assignerShortName": "GRAFANA",
"cveId": "CVE-2026-33382",
"datePublished": "2026-07-10T14:58:23.329Z",
"dateReserved": "2026-03-19T07:55:06.978Z",
"dateUpdated": "2026-08-27T17:22:28.355Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-13720 (GCVE-0-2026-13720)
Vulnerability from cvelistv5 – Published: 2026-09-30 11:06 – Updated: 2026-09-30 15:28
VLAI
EPSS
VEX
Title
Editor can forge file-provisioning provenance on dashboards via the dashboard API
Summary
An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations) when creating a dashboard through the dashboard API, because these fields were stored without an authorization check. The dashboard then appears file-provisioned, and administrators can no longer update or delete it through Grafana. The impact is limited to the same organization and no data is exposed.
Severity
5.4 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 13:55 UTC
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://grafana.com/security/security-advisories/… | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Grafana | Grafana OSS |
Affected:
12.0.0 , ≤ 12.0.10
(semver)
Affected: 12.1.0 , ≤ 12.1.10 (semver) Affected: 12.2.0 , ≤ 12.2.11 (semver) Affected: 12.3.0 , ≤ 12.3.11 (semver) Affected: 12.4.0 , < 12.4.12 (semver) Affected: 13.0.0 , < 13.0.10 (semver) Affected: 13.1.0 , < 13.1.7 (semver) Affected: 13.2.0 , < 13.2.3 (semver) |
|
| Grafana | Grafana Enterprise |
Affected:
12.0.0 , ≤ 12.0.10
(semver)
Affected: 12.1.0 , ≤ 12.1.10 (semver) Affected: 12.2.0 , ≤ 12.2.11 (semver) Affected: 12.3.0 , ≤ 12.3.11 (semver) Affected: 12.4.0 , < 12.4.12 (semver) Affected: 13.0.0 , < 13.0.10 (semver) Affected: 13.1.0 , < 13.1.7 (semver) Affected: 13.2.0 , < 13.2.3 (semver) |
Date Public
2026-09-29 07:44
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-13720",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T13:55:59.494551Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T15:28:07.969Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Grafana OSS",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "12.0.10",
"status": "affected",
"version": "12.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.1.10",
"status": "affected",
"version": "12.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.2.11",
"status": "affected",
"version": "12.2.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.3.11",
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThan": "12.4.12",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThan": "13.0.10",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThan": "13.1.7",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
},
{
"lessThan": "13.2.3",
"status": "affected",
"version": "13.2.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Grafana Enterprise",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "12.0.10",
"status": "affected",
"version": "12.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.1.10",
"status": "affected",
"version": "12.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.2.11",
"status": "affected",
"version": "12.2.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.3.11",
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThan": "12.4.12",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThan": "13.0.10",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThan": "13.1.7",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
},
{
"lessThan": "13.2.3",
"status": "affected",
"version": "13.2.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "arang (Researcher)"
}
],
"datePublic": "2026-09-29T07:44:02.000Z",
"descriptions": [
{
"lang": "en",
"value": "An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations) when creating a dashboard through the dashboard API, because these fields were stored without an authorization check. The dashboard then appears file-provisioned, and administrators can no longer update or delete it through Grafana. The impact is limited to the same organization and no data is exposed."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-285",
"description": "CWE-285",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-915",
"description": "CWE-915",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-345",
"description": "CWE-345",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T11:06:38.177Z",
"orgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"shortName": "GRAFANA"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://grafana.com/security/security-advisories/cve-2026-13720"
}
],
"source": {
"discovery": "BUG_BOUNTY"
},
"title": "Editor can forge file-provisioning provenance on dashboards via the dashboard API"
}
},
"cveMetadata": {
"assignerOrgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"assignerShortName": "GRAFANA",
"cveId": "CVE-2026-13720",
"datePublished": "2026-09-30T11:06:38.177Z",
"dateReserved": "2026-06-29T14:11:02.739Z",
"dateUpdated": "2026-09-30T15:28:07.969Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-13719 (GCVE-0-2026-13719)
Vulnerability from cvelistv5 – Published: 2026-09-30 11:06 – Updated: 2026-09-30 14:29
VLAI
EPSS
VEX
Title
Alert rules in restricted folders disclosed via the alert rules list API
Summary
An authenticated user can list alert rules stored in folders they are not allowed to read through the alert rules API list endpoint. When the set of folders the user may read was empty, the folder restriction was dropped and every alert rule in the organization was returned. From Grafana 13.1.0, any user can trigger this with a folder filter. The exposed data is rule configuration; data source credentials are not exposed.
Severity
4.3 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 14:29 UTC
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://grafana.com/security/security-advisories/… | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Grafana | Grafana Enterprise |
Affected:
12.3.0 , ≤ 12.3.11
(semver)
Affected: 12.4.0 , < 12.4.12 (semver) Affected: 13.0.0 , < 13.0.10 (semver) Affected: 13.1.0 , < 13.1.7 (semver) Affected: 13.2.0 , < 13.2.3 (semver) |
|
| Grafana | Grafana OSS |
Affected:
12.3.0 , ≤ 12.3.11
(semver)
Affected: 12.4.0 , < 12.4.12 (semver) Affected: 13.0.0 , < 13.0.10 (semver) Affected: 13.1.0 , < 13.1.7 (semver) Affected: 13.2.0 , < 13.2.3 (semver) |
Date Public
2026-09-29 07:44
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-13719",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T14:29:01.284869Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T14:29:13.891Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Grafana Enterprise",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "12.3.11",
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThan": "12.4.12",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThan": "13.0.10",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThan": "13.1.7",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
},
{
"lessThan": "13.2.3",
"status": "affected",
"version": "13.2.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Grafana OSS",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "12.3.11",
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThan": "12.4.12",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThan": "13.0.10",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThan": "13.1.7",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
},
{
"lessThan": "13.2.3",
"status": "affected",
"version": "13.2.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "mon3m"
}
],
"datePublic": "2026-09-29T07:44:02.000Z",
"descriptions": [
{
"lang": "en",
"value": "An authenticated user can list alert rules stored in folders they are not allowed to read through the alert rules API list endpoint. When the set of folders the user may read was empty, the folder restriction was dropped and every alert rule in the organization was returned. From Grafana 13.1.0, any user can trigger this with a folder filter. The exposed data is rule configuration; data source credentials are not exposed."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-200",
"description": "CWE-200",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T13:05:14.113Z",
"orgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"shortName": "GRAFANA"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://grafana.com/security/security-advisories/cve-2026-13719"
}
],
"source": {
"discovery": "BUG_BOUNTY"
},
"title": "Alert rules in restricted folders disclosed via the alert rules list API"
}
},
"cveMetadata": {
"assignerOrgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"assignerShortName": "GRAFANA",
"cveId": "CVE-2026-13719",
"datePublished": "2026-09-30T11:06:38.172Z",
"dateReserved": "2026-06-29T14:10:37.534Z",
"dateUpdated": "2026-09-30T14:29:13.891Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-81842 (GCVE-0-2026-81842)
Vulnerability from cvelistv5 – Published: 2026-09-29 20:50 – Updated: 2026-09-30 15:28
VLAI
EPSS
VEX
Title
Library panel can be moved into a folder without library panel create permission
Summary
An authenticated user with edit permission on one folder can move a library panel into another folder where they only have view permission, through the library elements API or the equivalent App Platform resource. The update path did not check library panel create permission on the destination folder (incorrect authorization). No data from the destination folder is disclosed, and existing content there cannot be changed.
Severity
4.3 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-30 15:04 UTC
CWE
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://grafana.com/security/security-advisories/… | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Grafana | Grafana Enterprise |
Affected:
12.1.0 , ≤ 12.1.10
(semver)
Affected: 12.2.0 , ≤ 12.2.11 (semver) Affected: 12.3.0 , ≤ 12.3.11 (semver) Affected: 12.4.0 , < 12.4.12 (semver) Affected: 13.0.0 , < 13.0.10 (semver) |
|
| Grafana | Grafana OSS |
Affected:
12.1.0 , ≤ 12.1.10
(semver)
Affected: 12.2.0 , ≤ 12.2.11 (semver) Affected: 12.3.0 , ≤ 12.3.11 (semver) Affected: 12.4.0 , < 12.4.12 (semver) Affected: 13.0.0 , < 13.0.10 (semver) |
Date Public
2026-09-29 07:44
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-81842",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-30T15:04:07.785889Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T15:28:16.203Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Grafana Enterprise",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "12.1.10",
"status": "affected",
"version": "12.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.2.11",
"status": "affected",
"version": "12.2.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.3.11",
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThan": "12.4.12",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThan": "13.0.10",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Grafana OSS",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "12.1.10",
"status": "affected",
"version": "12.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.2.11",
"status": "affected",
"version": "12.2.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.3.11",
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThan": "12.4.12",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThan": "13.0.10",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Dohyun Choi, CIS Lab, SeoulTech"
}
],
"datePublic": "2026-09-29T07:44:02.000Z",
"descriptions": [
{
"lang": "en",
"value": "An authenticated user with edit permission on one folder can move a library panel into another folder where they only have view permission, through the library elements API or the equivalent App Platform resource. The update path did not check library panel create permission on the destination folder (incorrect authorization). No data from the destination folder is disclosed, and existing content there cannot be changed."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 4.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T13:05:14.168Z",
"orgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"shortName": "GRAFANA"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://grafana.com/security/security-advisories/cve-2026-81842"
}
],
"source": {
"discovery": "BUG_BOUNTY"
},
"title": "Library panel can be moved into a folder without library panel create permission"
}
},
"cveMetadata": {
"assignerOrgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"assignerShortName": "GRAFANA",
"cveId": "CVE-2026-81842",
"datePublished": "2026-09-29T20:50:01.257Z",
"dateReserved": "2026-08-27T15:48:54.245Z",
"dateUpdated": "2026-09-30T15:28:16.203Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-81841 (GCVE-0-2026-81841)
Vulnerability from cvelistv5 – Published: 2026-09-29 20:35 – Updated: 2026-09-30 13:05
VLAI
EPSS
VEX
Title
Paused shared dashboard access tokens still expose data source configuration
Summary
Pausing a shared (public) dashboard did not revoke its access token for the endpoints that serve frontend bootstrap data. Anyone holding the link to a paused shared dashboard could still retrieve, without authenticating, the configuration of the dashboard's data sources, including stored credentials for data sources using browser access (missing authorization). Deleting the shared dashboard does revoke the token.
Severity
5.3 (Medium)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-29 20:55 UTC
CWE
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://grafana.com/security/security-advisories/… | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Grafana | Grafana Enterprise |
Affected:
11.6.0 , ≤ 11.6.17
(semver)
Affected: 12.0.0 , ≤ 12.0.10 (semver) Affected: 12.1.0 , ≤ 12.1.10 (semver) Affected: 12.2.0 , ≤ 12.2.11 (semver) Affected: 12.3.0 , ≤ 12.3.11 (semver) Affected: 12.4.0 , < 12.4.12 (semver) Affected: 13.0.0 , < 13.0.10 (semver) Affected: 13.1.0 , < 13.1.7 (semver) Affected: 13.2.0 , < 13.2.3 (semver) |
|
| Grafana | Grafana OSS |
Affected:
11.6.0 , ≤ 11.6.17
(semver)
Affected: 12.0.0 , ≤ 12.0.10 (semver) Affected: 12.1.0 , ≤ 12.1.10 (semver) Affected: 12.2.0 , ≤ 12.2.11 (semver) Affected: 12.3.0 , ≤ 12.3.11 (semver) Affected: 12.4.0 , < 12.4.12 (semver) Affected: 13.0.0 , < 13.0.10 (semver) Affected: 13.1.0 , < 13.1.7 (semver) Affected: 13.2.0 , < 13.2.3 (semver) |
Date Public
2026-09-29 07:44
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-81841",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-29T20:55:29.746576Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T21:01:59.754Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Grafana Enterprise",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "11.6.17",
"status": "affected",
"version": "11.6.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.0.10",
"status": "affected",
"version": "12.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.1.10",
"status": "affected",
"version": "12.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.2.11",
"status": "affected",
"version": "12.2.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.3.11",
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThan": "12.4.12",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThan": "13.0.10",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThan": "13.1.7",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
},
{
"lessThan": "13.2.3",
"status": "affected",
"version": "13.2.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Grafana OSS",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "11.6.17",
"status": "affected",
"version": "11.6.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.0.10",
"status": "affected",
"version": "12.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.1.10",
"status": "affected",
"version": "12.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.2.11",
"status": "affected",
"version": "12.2.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.3.11",
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThan": "12.4.12",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThan": "13.0.10",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThan": "13.1.7",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
},
{
"lessThan": "13.2.3",
"status": "affected",
"version": "13.2.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Yeonoh Park @ CIS Lab, SeoulTech"
}
],
"datePublic": "2026-09-29T07:44:02.000Z",
"descriptions": [
{
"lang": "en",
"value": "Pausing a shared (public) dashboard did not revoke its access token for the endpoints that serve frontend bootstrap data. Anyone holding the link to a paused shared dashboard could still retrieve, without authenticating, the configuration of the dashboard\u0027s data sources, including stored credentials for data sources using browser access (missing authorization). Deleting the shared dashboard does revoke the token."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T13:05:14.107Z",
"orgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"shortName": "GRAFANA"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://grafana.com/security/security-advisories/cve-2026-81841"
}
],
"source": {
"discovery": "BUG_BOUNTY"
},
"title": "Paused shared dashboard access tokens still expose data source configuration"
}
},
"cveMetadata": {
"assignerOrgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"assignerShortName": "GRAFANA",
"cveId": "CVE-2026-81841",
"datePublished": "2026-09-29T20:35:57.152Z",
"dateReserved": "2026-08-27T15:33:30.272Z",
"dateUpdated": "2026-09-30T13:05:14.107Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-15815 (GCVE-0-2026-15815)
Vulnerability from cvelistv5 – Published: 2026-09-17 20:47 – Updated: 2026-09-19 03:56
VLAI
EPSS
VEX
Title
CVE-2026-15815 CVE Record
Summary
Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when
extracting plugin archives. A crafted plugin archive can chain relative symbolic link
entries to escape the plugin installation directory, writing arbitrary files and an
executable backend binary outside that directory. The dropped executable runs with the
privileges of the Grafana server process, resulting in remote code execution.
Plugin archives are extracted before their signature is verified, so a valid plugin
signature does not prevent the write. An operator can therefore be affected by
installing a plugin that appears legitimate, as well as by installing a plugin from an
arbitrary archive using grafana-cli, the GF_INSTALL_PLUGINS environment variable, or
preinstall configuration.
Grafana Enterprise is affected because it includes the same plugin extraction code as
Grafana OSS.
Severity
8.8 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-18 00:00 UTC
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://grafana.com/security/security-advisories/… | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Grafana | Grafana OSS |
Affected:
11.6.0 , ≤ 11.6.17
(semver)
Affected: 12.0.0 (semver) Affected: 12.1.0 (semver) Affected: 12.2.0 (semver) Affected: 12.3.0 (semver) Affected: 12.4.0 , ≤ 12.4.10 (semver) Affected: 13.0.0 , ≤ 13.0.8 (semver) Affected: 13.1.0 , ≤ 13.1.5 (semver) Affected: 13.2.0 , ≤ 13.2.1 (semver) |
|
| Grafana | Grafana Enterprise |
Affected:
11.6.0 , ≤ 11.6.17
(semver)
Affected: 12.0.0 (semver) Affected: 12.1.0 (semver) Affected: 12.2.0 (semver) Affected: 12.3.0 (semver) Affected: 12.4.0 , ≤ 12.4.10 (semver) Affected: 13.0.0 , ≤ 13.0.8 (semver) Affected: 13.1.0 , ≤ 13.1.5 (semver) Affected: 13.2.0 , ≤ 13.2.1 (semver) |
Date Public
2026-08-15 11:19
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-15815",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-18T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-19T03:56:26.777Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Grafana OSS",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "11.6.17",
"status": "affected",
"version": "11.6.0",
"versionType": "semver"
},
{
"status": "affected",
"version": "12.0.0",
"versionType": "semver"
},
{
"status": "affected",
"version": "12.1.0",
"versionType": "semver"
},
{
"status": "affected",
"version": "12.2.0",
"versionType": "semver"
},
{
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.4.10",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.0.8",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.1.5",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.2.1",
"status": "affected",
"version": "13.2.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Grafana Enterprise",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "11.6.17",
"status": "affected",
"version": "11.6.0",
"versionType": "semver"
},
{
"status": "affected",
"version": "12.0.0",
"versionType": "semver"
},
{
"status": "affected",
"version": "12.1.0",
"versionType": "semver"
},
{
"status": "affected",
"version": "12.2.0",
"versionType": "semver"
},
{
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.4.10",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.0.8",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.1.5",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.2.1",
"status": "affected",
"version": "13.2.0",
"versionType": "semver"
}
]
}
],
"datePublic": "2026-08-15T11:19:01.400Z",
"descriptions": [
{
"lang": "en",
"value": "Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when\nextracting plugin archives. A crafted plugin archive can chain relative symbolic link\nentries to escape the plugin installation directory, writing arbitrary files and an\nexecutable backend binary outside that directory. The dropped executable runs with the\nprivileges of the Grafana server process, resulting in remote code execution.\n\nPlugin archives are extracted before their signature is verified, so a valid plugin\nsignature does not prevent the write. An operator can therefore be affected by\ninstalling a plugin that appears legitimate, as well as by installing a plugin from an\narbitrary archive using grafana-cli, the GF_INSTALL_PLUGINS environment variable, or\npreinstall configuration.\n\nGrafana Enterprise is affected because it includes the same plugin extraction code as\nGrafana OSS."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-59",
"description": "CWE-59",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-94",
"description": "CWE-94",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "CWE-22",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T20:47:01.006Z",
"orgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"shortName": "GRAFANA"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://grafana.com/security/security-advisories/cve-2026-15815"
}
],
"source": {
"discovery": "INTERNAL_FINDING"
},
"title": "CVE-2026-15815 CVE Record",
"x_generator": {
"engine": "cvelib 1.8.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"assignerShortName": "GRAFANA",
"cveId": "CVE-2026-15815",
"datePublished": "2026-09-17T20:47:01.006Z",
"dateReserved": "2026-07-15T11:15:50.200Z",
"dateUpdated": "2026-09-19T03:56:26.777Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-76154 (GCVE-0-2026-76154)
Vulnerability from cvelistv5 – Published: 2026-09-17 20:22 – Updated: 2026-09-18 17:34
VLAI
EPSS
VEX
Title
CVE-2026-76154 CVE Record
Summary
A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user's session by hosting a malicious style configuration, enabling escalation to Org Admin.
Severity
7.3 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-18 17:33 UTC
CWE
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://grafana.com/security/security-advisories/… | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Grafana | Grafana OSS |
Affected:
12.3.0
(semver)
Affected: 12.4.0 , ≤ 12.4.10 (semver) Affected: 13.0.0 , ≤ 13.0.8 (semver) Affected: 13.1.0 , ≤ 13.1.5 (semver) Affected: 13.2.0 , ≤ 13.2.1 (semver) |
|
| Grafana | Grafana Enterprise |
Affected:
12.3.0
(semver)
Affected: 12.4.0 , ≤ 12.4.10 (semver) Affected: 13.0.0 , ≤ 13.0.8 (semver) Affected: 13.1.0 , ≤ 13.1.5 (semver) Affected: 13.2.0 , ≤ 13.2.1 (semver) |
Date Public
2026-08-19 07:45
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-76154",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-18T17:33:54.472083Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-18T17:34:10.251Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Grafana OSS",
"vendor": "Grafana",
"versions": [
{
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.4.10",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.0.8",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.1.5",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.2.1",
"status": "affected",
"version": "13.2.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Grafana Enterprise",
"vendor": "Grafana",
"versions": [
{
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.4.10",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.0.8",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.1.5",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.2.1",
"status": "affected",
"version": "13.2.0",
"versionType": "semver"
}
]
}
],
"datePublic": "2026-08-19T07:45:08.551Z",
"descriptions": [
{
"lang": "en",
"value": "A stored cross-site scripting vulnerability in the Geomap panel\u0027s MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user\u0027s session by hosting a malicious style configuration, enabling escalation to Org Admin."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T20:22:55.718Z",
"orgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"shortName": "GRAFANA"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://grafana.com/security/security-advisories/cve-2026-76154"
}
],
"source": {
"discovery": "BUG_BOUNTY"
},
"title": "CVE-2026-76154 CVE Record",
"x_generator": {
"engine": "cvelib 1.8.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"assignerShortName": "GRAFANA",
"cveId": "CVE-2026-76154",
"datePublished": "2026-09-17T20:22:55.718Z",
"dateReserved": "2026-08-19T07:45:07.588Z",
"dateUpdated": "2026-09-18T17:34:10.251Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-14199 (GCVE-0-2026-14199)
Vulnerability from cvelistv5 – Published: 2026-09-02 16:06 – Updated: 2026-09-03 08:07
VLAI
EPSS
VEX
Title
Session takeover via Auth Proxy cache key collision
Summary
Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while that user's cache entry is live, is authenticated as that user, up to Administrator (authentication bypass by spoofing).
Severity
7.1 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-02 00:00 UTC
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://grafana.com/security/security-advisories/… | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Grafana | Grafana Enterprise |
Affected:
11.0.0 , ≤ 11.6.17
(semver)
Affected: 12.0.0 , ≤ 12.2.11 (semver) Affected: 12.3.0 , ≤ 12.3.11 (semver) Affected: 12.4.0 , ≤ 12.4.9 (semver) Affected: 13.0.0 , ≤ 13.0.7 (semver) Affected: 13.1.0 , ≤ 13.1.4 (semver) Affected: 13.2.0 , ≤ 13.2.0 (semver) |
|
| Grafana | Grafana OSS |
Affected:
11.0.0 , ≤ 11.6.17
(semver)
Affected: 12.0.0 , ≤ 12.2.11 (semver) Affected: 12.3.0 , ≤ 12.3.11 (semver) Affected: 12.4.0 , ≤ 12.4.9 (semver) Affected: 13.0.0 , ≤ 13.0.7 (semver) Affected: 13.1.0 , ≤ 13.1.4 (semver) Affected: 13.2.0 , ≤ 13.2.0 (semver) |
Date Public
2026-09-02 09:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-14199",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-02T00:00:00+00:00",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-03T03:56:40.337Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Grafana Enterprise",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "11.6.17",
"status": "affected",
"version": "11.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.2.11",
"status": "affected",
"version": "12.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.3.11",
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.4.9",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.0.7",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.1.4",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.2.0",
"status": "affected",
"version": "13.2.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Grafana OSS",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "11.6.17",
"status": "affected",
"version": "11.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.2.11",
"status": "affected",
"version": "12.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.3.11",
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.4.9",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.0.7",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.1.4",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.2.0",
"status": "affected",
"version": "13.2.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "rebelarch (Researcher)"
}
],
"datePublic": "2026-09-02T09:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user\u0027s, while that user\u0027s cache entry is live, is authenticated as that user, up to Administrator (authentication bypass by spoofing)."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-290",
"description": "CWE-290",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-1023",
"description": "CWE-1023",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-03T08:07:46.925Z",
"orgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"shortName": "GRAFANA"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://grafana.com/security/security-advisories/cve-2026-14199"
}
],
"source": {
"discovery": "BUG_BOUNTY"
},
"title": "Session takeover via Auth Proxy cache key collision",
"x_generator": {
"engine": "cvelib 1.8.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"assignerShortName": "GRAFANA",
"cveId": "CVE-2026-14199",
"datePublished": "2026-09-02T16:06:28.165Z",
"dateReserved": "2026-06-30T09:16:17.958Z",
"dateUpdated": "2026-09-03T08:07:46.925Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-19475 (GCVE-0-2026-19475)
Vulnerability from cvelistv5 – Published: 2026-09-02 15:56 – Updated: 2026-09-03 08:08
VLAI
EPSS
VEX
Title
SQL Data Source Plugin: OOM DoS via $__timeGroup macro
Summary
An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafana's regex-based macro parsing does not reject. Evaluating the injected macro causes uncontrolled memory consumption that can terminate the Grafana server process, resulting in a denial of service. The Microsoft SQL Server, PostgreSQL, and MySQL data sources are affected.
Severity
6.5 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-02 18:00 UTC
CWE
- CWE-400 - Uncontrolled Resource Consumption
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://grafana.com/security/security-advisories/… | vendor-advisory |
Impacted products
4 products
| Vendor | Product | Version | |
|---|---|---|---|
| Grafana | PostgreSQL Datasource |
Affected:
13.0.0 , ≤ 13.0.1
(semver)
|
|
| Grafana | MySQL Datasource |
Affected:
13.0.0 , ≤ 13.0.2
(semver)
|
|
| Grafana | Grafana OSS |
Affected:
11.6.0 , ≤ 11.6.16
(semver)
Affected: 12.0.0 , ≤ 12.0.10 (semver) Affected: 12.1.0 , ≤ 12.1.10 (semver) Affected: 12.2.0 , ≤ 12.2.10 (semver) Affected: 12.3.0 , ≤ 12.3.11 (semver) Affected: 12.4.0 , ≤ 12.4.9 (semver) Affected: 13.0.0 , ≤ 13.0.7 (semver) Affected: 13.1.0 , ≤ 13.1.4 (semver) |
|
| Grafana | Microsoft SQL Server Datasource |
Affected:
13.0.0 , ≤ 13.0.1
(semver)
|
Date Public
2026-09-02 09:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-19475",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-02T18:00:46.819628Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-400",
"description": "CWE-400 Uncontrolled Resource Consumption",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-02T18:01:10.582Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "PostgreSQL Datasource",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "13.0.1",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "MySQL Datasource",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "13.0.2",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Grafana OSS",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "11.6.16",
"status": "affected",
"version": "11.6.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.0.10",
"status": "affected",
"version": "12.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.1.10",
"status": "affected",
"version": "12.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.2.10",
"status": "affected",
"version": "12.2.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.3.11",
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.4.9",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.0.7",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.1.4",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Microsoft SQL Server Datasource",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "13.0.1",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "khanmarshal (Researcher)"
}
],
"datePublic": "2026-09-02T09:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafana\u0027s regex-based macro parsing does not reject. Evaluating the injected macro causes uncontrolled memory consumption that can terminate the Grafana server process, resulting in a denial of service. The Microsoft SQL Server, PostgreSQL, and MySQL data sources are affected."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-03T08:08:02.649Z",
"orgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"shortName": "GRAFANA"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://grafana.com/security/security-advisories/cve-2026-19475"
}
],
"source": {
"discovery": "BUG_BOUNTY"
},
"title": "SQL Data Source Plugin: OOM DoS via $__timeGroup macro",
"x_generator": {
"engine": "cvelib 1.8.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"assignerShortName": "GRAFANA",
"cveId": "CVE-2026-19475",
"datePublished": "2026-09-02T15:56:33.568Z",
"dateReserved": "2026-08-10T14:51:01.083Z",
"dateUpdated": "2026-09-03T08:08:02.649Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-19197 (GCVE-0-2026-19197)
Vulnerability from cvelistv5 – Published: 2026-08-26 08:50 – Updated: 2026-08-27 17:22
VLAI
EPSS
VEX
Title
Broken access control in dashboard snapshots
Summary
A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot's secret delete key using only its public share key (broken access control).
Severity
6.3 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-26 13:42 UTC
CWE
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://grafana.com/security/security-advisories/… | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Grafana | Grafana OSS |
Affected:
12.4.0 , < 12.4.8
(semver)
Affected: 13.0.0 , < 13.0.6 (semver) Affected: 13.1.0 , < 13.1.3 (semver) |
|
| Grafana | Grafana Enterprise |
Affected:
12.4.0 , < 12.4.8
(semver)
Affected: 13.0.0 , < 13.0.6 (semver) Affected: 13.1.0 , < 13.1.3 (semver) |
Date Public
2026-08-06 20:25
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-19197",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-26T13:42:34.663264Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-26T13:48:49.617Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Grafana OSS",
"vendor": "Grafana",
"versions": [
{
"lessThan": "12.4.8",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThan": "13.0.6",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThan": "13.1.3",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Grafana Enterprise",
"vendor": "Grafana",
"versions": [
{
"lessThan": "12.4.8",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThan": "13.0.6",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThan": "13.1.3",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Snyk"
}
],
"datePublic": "2026-08-06T20:25:59.097Z",
"descriptions": [
{
"lang": "en",
"value": "A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot\u0027s secret delete key using only its public share key (broken access control)."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "CWE-862",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T17:22:36.904Z",
"orgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"shortName": "GRAFANA"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://grafana.com/security/security-advisories/cve-2026-19197"
}
],
"source": {
"discovery": "EXTERNAL_REPORT"
},
"title": "Broken access control in dashboard snapshots",
"x_generator": {
"engine": "cvelib 1.8.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"assignerShortName": "GRAFANA",
"cveId": "CVE-2026-19197",
"datePublished": "2026-08-26T08:50:27.854Z",
"dateReserved": "2026-08-06T20:25:58.163Z",
"dateUpdated": "2026-08-27T17:22:36.904Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-17033 (GCVE-0-2026-17033)
Vulnerability from cvelistv5 – Published: 2026-08-24 13:52 – Updated: 2026-08-27 17:22
VLAI
EPSS
VEX
Title
CVE-2026-17033 CVE Record
Summary
An authenticated attacker with Editor access or alert.instances.external:write can submit an external Alertmanager alert containing a controlled generatorURL. The attacker is authorized to create the alert, but not to execute script in another user's Grafana session.
Grafana renders alert.generatorURL directly as the Alert Details See source LinkButton href without URL-scheme sanitization or a safe-protocol allowlist. The click interceptor's :// heuristic can be bypassed by placing :// inside a JavaScript comment. When a user with read access clicks See source, the browser executes attacker-controlled JavaScript in the Grafana origin with the clicking user's permissions.
Severity
6.8 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-24 15:10 UTC
CWE
- CWE-79 - IMPROPER NEUTRALIZATION OF INPUT DURING WEB PAGE GENERATION ('CROSS-SITE SCRIPTING')
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://grafana.com/security/security-advisories/… | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Grafana | Grafana OSS |
Affected:
0 , ≤ 12.3.11
(semver)
Affected: 12.4.0 , ≤ 12.4.9 (semver) Affected: 13.0.0 , ≤ 13.0.7 (semver) |
Date Public
2026-08-24 12:11
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-17033",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-24T15:10:56.482893Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-24T15:11:08.143Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Grafana OSS",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "12.3.11",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.4.9",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.0.7",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "nlgbao1340"
}
],
"datePublic": "2026-08-24T12:11:43.533Z",
"descriptions": [
{
"lang": "en",
"value": "An authenticated attacker with Editor access or alert.instances.external:write can submit an external Alertmanager alert containing a controlled generatorURL. The attacker is authorized to create the alert, but not to execute script in another user\u0027s Grafana session.\n\nGrafana renders alert.generatorURL directly as the Alert Details See source LinkButton href without URL-scheme sanitization or a safe-protocol allowlist. The click interceptor\u0027s :// heuristic can be bypassed by placing :// inside a JavaScript comment. When a user with read access clicks See source, the browser executes attacker-controlled JavaScript in the Grafana origin with the clicking user\u0027s permissions."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 6.8,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79: IMPROPER NEUTRALIZATION OF INPUT DURING WEB PAGE GENERATION (\u0027CROSS-SITE SCRIPTING\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T17:22:43.827Z",
"orgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"shortName": "GRAFANA"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://grafana.com/security/security-advisories/cve-2026-17033"
}
],
"source": {
"discovery": "BUG_BOUNTY"
},
"title": "CVE-2026-17033 CVE Record",
"x_generator": {
"engine": "cvelib 1.8.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"assignerShortName": "GRAFANA",
"cveId": "CVE-2026-17033",
"datePublished": "2026-08-24T13:52:26.910Z",
"dateReserved": "2026-07-24T12:11:43.417Z",
"dateUpdated": "2026-08-27T17:22:43.827Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-17183 (GCVE-0-2026-17183)
Vulnerability from cvelistv5 – Published: 2026-08-19 17:30 – Updated: 2026-08-27 17:22
VLAI
EPSS
VEX
Title
CVE-2026-17183 CVE Record
Summary
An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a server-side expression while referencing a real datasource UID (incorrect authorization). This can expose data accessible through Grafana's configured datasource credentials to users who lack permission to query that datasource.
Severity
7.1 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-19 18:40 UTC
CWE
- CWE-863 - INCORRECT AUTHORIZATION
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://grafana.com/security/security-advisories/… | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Grafana | Grafana OSS |
Affected:
8.4.0 , < 12.3.11
(semver)
Affected: 12.4.0 , < 12.4.9 (semver) Affected: 13.0.0 , < 13.0.7 (semver) Affected: 13.1.0 , < 13.1.4 (semver) |
|
| Grafana | Grafana Enterprise |
Affected:
8.4.0 , < 12.3.11
(semver)
Affected: 12.4.0 , < 12.4.9 (semver) Affected: 13.0.0 , < 13.0.7 (semver) Affected: 13.1.0 , < 13.1.4 (semver) |
Date Public
2026-07-24 18:38
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-17183",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-19T18:40:28.206524Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-19T18:42:03.891Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Grafana OSS",
"vendor": "Grafana",
"versions": [
{
"lessThan": "12.3.11",
"status": "affected",
"version": "8.4.0",
"versionType": "semver"
},
{
"lessThan": "12.4.9",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThan": "13.0.7",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThan": "13.1.4",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Grafana Enterprise",
"vendor": "Grafana",
"versions": [
{
"lessThan": "12.3.11",
"status": "affected",
"version": "8.4.0",
"versionType": "semver"
},
{
"lessThan": "12.4.9",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThan": "13.0.7",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThan": "13.1.4",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "czarflix"
}
],
"datePublic": "2026-07-24T18:38:02.945Z",
"descriptions": [
{
"lang": "en",
"value": "An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a server-side expression while referencing a real datasource UID (incorrect authorization). This can expose data accessible through Grafana\u0027s configured datasource credentials to users who lack permission to query that datasource."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863: INCORRECT AUTHORIZATION",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T17:22:31.524Z",
"orgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"shortName": "GRAFANA"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://grafana.com/security/security-advisories/cve-2026-17183"
}
],
"source": {
"discovery": "BUG_BOUNTY"
},
"title": "CVE-2026-17183 CVE Record",
"x_generator": {
"engine": "cvelib 1.8.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"assignerShortName": "GRAFANA",
"cveId": "CVE-2026-17183",
"datePublished": "2026-08-19T17:30:06.798Z",
"dateReserved": "2026-07-24T18:38:02.221Z",
"dateUpdated": "2026-08-27T17:22:31.524Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-11817 (GCVE-0-2026-11817)
Vulnerability from cvelistv5 – Published: 2026-08-17 21:28 – Updated: 2026-09-14 10:16
VLAI
EPSS
VEX
Title
CVE-2026-11817 CVE Record
Summary
This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted. In a multi-organization stack, a user who is an Org Admin of a single organization can call GET /api/access-control/users/permissions/search?actionPrefix=dashboards: and receive permission data belonging to other organizations. The disclosed data is limited to dashboard and folder identifiers (UIDs) and per-user permission/scope mappings (which user holds which access on which dashboard). Dashboard contents, panels, query results, datasource credentials, secrets, and personal data are not exposed. This is a limited cross-organization information disclosure affecting multi-org deployments only.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-18 15:22 UTC
CWE
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://grafana.com/security/security-advisories/… | vendor-advisory |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Grafana | Grafana OSS |
Affected:
12.4.0 , ≤ 12.4.5
(semver)
Affected: 11.2.0 , ≤ 11.6.16 (semver) Affected: 13.0.0 , ≤ 13.0.3 (semver) Affected: 13.1.0 , ≤ 13.1.0 (semver) Affected: 12.2.0 , ≤ 12.2.10 (semver) Affected: 12.3.0 , ≤ 12.3.8 (semver) |
|
| Grafana | Grafana Enterprise |
Affected:
13.0.0 , ≤ 13.0.3
(semver)
Affected: 12.2.0 , ≤ 12.2.10 (semver) Affected: 11.2.0 , ≤ 11.6.16 (semver) Affected: 12.3.0 , ≤ 12.3.8 (semver) Affected: 12.4.0 , ≤ 12.4.5 (semver) Affected: 13.1.0 , ≤ 13.1.0 (semver) |
Date Public
2026-07-17 14:01
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-11817",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-18T15:22:39.226844Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-18T15:22:45.428Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Grafana OSS",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "12.4.5",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "11.6.16",
"status": "affected",
"version": "11.2.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.0.3",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.1.0",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.2.10",
"status": "affected",
"version": "12.2.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.3.8",
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
}
]
},
{
"defaultStatus": "unaffected",
"product": "Grafana Enterprise",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "13.0.3",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.2.10",
"status": "affected",
"version": "12.2.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "11.6.16",
"status": "affected",
"version": "11.2.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.3.8",
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.4.5",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.1.0",
"status": "affected",
"version": "13.1.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Harish Kolla"
}
],
"datePublic": "2026-07-17T14:01:45.422Z",
"descriptions": [
{
"lang": "en",
"value": "This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted. In a multi-organization stack, a user who is an Org Admin of a single organization can call GET /api/access-control/users/permissions/search?actionPrefix=dashboards: and receive permission data belonging to other organizations. The disclosed data is limited to dashboard and folder identifiers (UIDs) and per-user permission/scope mappings (which user holds which access on which dashboard). Dashboard contents, panels, query results, datasource credentials, secrets, and personal data are not exposed. This is a limited cross-organization information disclosure affecting multi-org deployments only."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "CWE-863",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-14T10:16:35.588Z",
"orgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"shortName": "GRAFANA"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://grafana.com/security/security-advisories/cve-2026-11817"
}
],
"source": {
"discovery": "BUG_BOUNTY"
},
"title": "CVE-2026-11817 CVE Record",
"x_generator": {
"engine": "cvelib 1.8.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"assignerShortName": "GRAFANA",
"cveId": "CVE-2026-11817",
"datePublished": "2026-08-17T21:28:17.497Z",
"dateReserved": "2026-06-09T16:24:38.153Z",
"dateUpdated": "2026-09-14T10:16:35.588Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-21723 (GCVE-0-2026-21723)
Vulnerability from cvelistv5 – Published: 2026-07-23 01:48 – Updated: 2026-08-27 17:22
VLAI
EPSS
VEX
Title
CVE-2026-21723 Record
Summary
The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anonymous access enabled.
Severity
5.3 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-07-23 14:15 UTC
CWE
- CWE-400 - Uncontrolled Resource Consumption
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://grafana.com/security/security-advisories/… | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Grafana | Grafana OSS |
Affected:
8.0.0 , ≤ 11.0.0
(semver)
Affected: 11.0.0 , ≤ 11.6.10 (semver) Affected: 12.0.0 , ≤ 12.0.9 (semver) Affected: 12.1.0 , ≤ 12.1.6 (semver) Affected: 12.2.0 , ≤ 12.2.4 (semver) Affected: 12.3.0 , ≤ 12.3.2 (semver) |
Date Public
2026-07-22 01:42
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-21723",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-23T14:15:50.650728Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-400",
"description": "CWE-400 Uncontrolled Resource Consumption",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-23T14:16:10.097Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Grafana OSS",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "11.0.0",
"status": "affected",
"version": "8.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "11.6.10",
"status": "affected",
"version": "11.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.0.9",
"status": "affected",
"version": "12.0.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.1.6",
"status": "affected",
"version": "12.1.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.2.4",
"status": "affected",
"version": "12.2.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "12.3.2",
"status": "affected",
"version": "12.3.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "nacl (Researcher)"
}
],
"datePublic": "2026-07-22T01:42:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anonymous access enabled."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T17:22:29.672Z",
"orgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"shortName": "GRAFANA"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://grafana.com/security/security-advisories/cve-2026-21723"
}
],
"source": {
"discovery": "BUG_BOUNTY"
},
"title": "CVE-2026-21723 Record",
"x_generator": {
"engine": "cvelib 1.8.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"assignerShortName": "GRAFANA",
"cveId": "CVE-2026-21723",
"datePublished": "2026-07-23T01:48:16.245Z",
"dateReserved": "2026-01-05T09:26:06.214Z",
"dateUpdated": "2026-08-27T17:22:29.672Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-8595 (GCVE-0-2026-8595)
Vulnerability from cvelistv5 – Published: 2026-07-10 14:59 – Updated: 2026-08-27 17:22
VLAI
EPSS
VEX
Title
Stored XSS in the table panel (TableNG)
Summary
A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting).
Severity
6.8 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-07-10 15:59 UTC
CWE
Assigner
References
1 reference
| URL | Tags |
|---|---|
| https://grafana.com/security/security-advisories/… | vendor-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Grafana | Grafana OSS |
Affected:
12.4.0 , ≤ 12.4.3
(semver)
Affected: 13.0.0 , ≤ 13.0.1 (semver) |
Date Public
2026-06-09 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-8595",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-10T15:59:08.422134Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-10T15:59:19.628Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Grafana OSS",
"vendor": "Grafana",
"versions": [
{
"lessThanOrEqual": "12.4.3",
"status": "affected",
"version": "12.4.0",
"versionType": "semver"
},
{
"lessThanOrEqual": "13.0.1",
"status": "affected",
"version": "13.0.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "avamost369 (Researcher)"
}
],
"datePublic": "2026-06-09T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting)."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 6.8,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L",
"version": "3.1"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T17:22:45.998Z",
"orgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"shortName": "GRAFANA"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://grafana.com/security/security-advisories/cve-2026-8595"
}
],
"source": {
"discovery": "BUG_BOUNTY"
},
"title": "Stored XSS in the table panel (TableNG)",
"x_generator": {
"engine": "cvelib 1.8.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "57da9224-a3e2-4646-9d0e-c4dc2e05e7da",
"assignerShortName": "GRAFANA",
"cveId": "CVE-2026-8595",
"datePublished": "2026-07-10T14:59:35.891Z",
"dateReserved": "2026-05-14T12:50:43.291Z",
"dateUpdated": "2026-08-27T17:22:45.998Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}