{"id":"CVE-2026-10601","title":"A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints","summary":"A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak inter…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","cwe":["CWE-22"],"vendor":"grafana","product":"grafana","affected":["grafana = 11.6.0"],"published":"2026-06-22","updated":"2026-07-10","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-10601","references":[{"url":"https://grafana.com/security/security-advisories/cve-2026-10601","label":"security@grafana.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-10601.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-10601"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2491359"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-10601"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-10601"},{"url":"https://access.redhat.com/errata/RHSA-2026:68143"},{"url":"https://access.redhat.com/errata/RHSA-2026:67573"},{"url":"https://access.redhat.com/errata/RHSA-2026:67605"},{"url":"https://access.redhat.com/errata/RHSA-2026:64525"},{"url":"https://access.redhat.com/errata/RHSA-2026:64585"},{"url":"https://access.redhat.com/errata/RHSA-2026:62527"},{"url":"https://access.redhat.com/errata/RHSA-2026:62537"},{"url":"https://github.com/grafana/grafana/pull/125789"},{"url":"https://github.com/grafana/grafana/commit/3fcdbc5a6e5c955bd42bd3715dd03cbad2b078c1"},{"url":"https://github.com/grafana/grafana/commit/42cdc39124912a8506a0c613c319c345aa950b29"},{"url":"https://github.com/grafana/grafana/commit/82ef13993059351bf21de35b8488bbd9b42df4f4"},{"url":"https://github.com/grafana/grafana/commit/d27d2eba9c509d16f214d290436a6ad0bd9c6c01"},{"url":"https://github.com/grafana/grafana/commit/dd5dc51681ff0133ddb2e206c2ea318713aeca16"},{"url":"https://github.com/grafana/grafana/commit/f70d3e480274a5dbd12006338c393f4b05d441ca"},{"url":"https://github.com/grafana/grafana/releases/tag/v11.6.15"},{"url":"https://github.com/grafana/grafana/releases/tag/v12.2.9"},{"url":"https://github.com/grafana/grafana/releases/tag/v12.3.7"},{"url":"https://github.com/grafana/grafana/releases/tag/v12.4.4"},{"url":"https://github.com/grafana/grafana/releases/tag/v13.0.2"},{"url":"https://github.com/advisories/GHSA-9493-h4f5-633x"},{"url":"https://github.com/grafana/grafana"}],"tags":["nvd","csaf","vex","red-hat","ghsa","go","osv"],"epss":0.00286,"epssPercentile":0.21353,"ingestedAt":"2026-07-11T13:13:24.663Z","patched":["hardened_images"],"aliases":["GHSA-9493-h4f5-633x","BIT-grafana-2026-10601"],"ecosystem":"go","slug":"CVE-2026-10601","body":"## Overview\n\nA user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative actions on the configured backend.\n\n## Affected\n\n- `grafana = 11.6.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Multicluster Global Hub, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Ceph Storage 5, Red Hat Ceph Storage 6, Red Hat Ceph Storage 7, Red Hat Ceph Storage 8, … · no fix planned: Multicluster Global Hub, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Ceph Storage 5, Red Hat Ceph Storage 6, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-10601.json)\n- **RHSA-2026:68143** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68143)\n- **RHSA-2026:67573** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67573)\n- **RHSA-2026:67605** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67605)\n- **RHSA-2026:64525** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:64525)\n- **RHSA-2026:64585** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:64585)\n- **RHSA-2026:62527** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:62527)\n- **RHSA-2026:62537** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:62537)\n\n## Package advisory (CVE-2026-10601)\n\nAffected packages:\n\n- `github.com/grafana/grafana >= 2.0.0-beta1, < 11.6.15`\n- `github.com/grafana/grafana >= 12.0.0, < 12.2.9`\n- `github.com/grafana/grafana >= 12.3.0, < 12.3.7`\n- `github.com/grafana/grafana >= 13.0.0, < 13.0.2`\n- `github.com/grafana/grafana >= 12.4.0, < 12.4.4`\n- `github.com/grafana/grafana < 1.9.2-0.20260616075434-82ef13993059`\n\nPatched in:\n\n- `github.com/grafana/grafana 1.9.2-0.20260616075434-82ef13993059`\n\nSource: https://github.com/advisories/GHSA-9493-h4f5-633x","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}