{"id":"CVE-2026-42129","title":"A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.","summary":"A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.","severity":"high","cvss":7.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","cwe":["CWE-22"],"vendor":"grafana","product":"loki_datasource","affected":["loki_datasource"],"published":"2026-06-22","updated":"2026-07-10","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-42129","references":[{"url":"https://grafana.com/security/security-advisories/cve-2026-42129","label":"security@grafana.com"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42129"},{"url":"https://github.com/grafana/grafana/commit/3fcdbc5a6e5c955bd42bd3715dd03cbad2b078c1"},{"url":"https://github.com/grafana/grafana/commit/42cdc39124912a8506a0c613c319c345aa950b29"},{"url":"https://github.com/grafana/grafana/commit/82ef13993059351bf21de35b8488bbd9b42df4f4"},{"url":"https://github.com/grafana/grafana/commit/d27d2eba9c509d16f214d290436a6ad0bd9c6c01"},{"url":"https://github.com/grafana/grafana/commit/dd5dc51681ff0133ddb2e206c2ea318713aeca16"},{"url":"https://github.com/grafana/grafana/commit/eeb08ceb020c4381242d8400e5878044e9877505"},{"url":"https://github.com/grafana/grafana/commit/f70d3e480274a5dbd12006338c393f4b05d441ca"},{"url":"https://github.com/grafana/grafana/releases/tag/v11.6.15"},{"url":"https://github.com/grafana/grafana/releases/tag/v12.2.9"},{"url":"https://github.com/grafana/grafana/releases/tag/v12.3.7"},{"url":"https://github.com/grafana/grafana/releases/tag/v12.4.4"},{"url":"https://github.com/grafana/grafana/releases/tag/v13.0.2"},{"url":"https://github.com/advisories/GHSA-f74p-cwhp-x2wx"},{"url":"https://github.com/grafana/grafana"}],"tags":["nvd","ghsa","go","osv"],"epss":0.00443,"epssPercentile":0.37913,"ingestedAt":"2026-07-11T13:13:24.678Z","aliases":["GHSA-f74p-cwhp-x2wx"],"ecosystem":"go","patched":["github.com/grafana/grafana 1.9.2-0.20260616075434-82ef13993059"],"slug":"CVE-2026-42129","body":"## Overview\n\nA user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.\n\n## Affected\n\n- `loki_datasource`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-42129)\n\nAffected packages:\n\n- `github.com/grafana/grafana >= 2.0.0-beta1, < 11.6.15`\n- `github.com/grafana/grafana >= 12.0.0, < 12.2.9`\n- `github.com/grafana/grafana >= 12.3.0, < 12.3.7`\n- `github.com/grafana/grafana >= 13.0.0, < 13.0.2`\n- `github.com/grafana/grafana >= 12.4.0, < 12.4.4`\n- `github.com/grafana/grafana < 1.9.2-0.20260616075434-82ef13993059`\n\nPatched in:\n\n- `github.com/grafana/grafana 1.9.2-0.20260616075434-82ef13993059`\n\nSource: https://github.com/advisories/GHSA-f74p-cwhp-x2wx","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":42.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}