CVE-2024-1442Medium· 6.0▾ SunlitA flaw was found in Grafana, where setting the Grafana API Data Source UID to '*' Grants Unrestricted Access, grants a user the ability to set the UID to '*' via the Grafana API poses a severe security risk. This issue enables unauthorized…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.8%
Last analysed / modified upstream
A flaw was found in Grafana, where setting the Grafana API Data Source UID to '' Grants Unrestricted Access, grants a user the ability to set the UID to '' via the Grafana API poses a severe security risk. This issue enables unauthorized access to read, query, edit, and delete all data sources within the organization. Such unrestricted access can lead to data breaches, manipulation, privacy violations, and compliance issues, emphasizing the critical importance of implementing stringent access controls and monitoring API usage.
grafana: Improper priviledge managent for users with data source permissions — rated Moderate by Red Hat. Released 2024-03-07, updated 2026-09-17.
Affected:
Fixed:
No fix planned:
Not affected:
For Red Hat Advanced Cluster Management for Kubernetes, see the following documentation for details on how to install the images:
https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.12/html/install/installing https://access.redhat.com/errata/RHSA-2024:8974 Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258
and
https://access.redhat.com/documentation/en-us/red_hat_ceph_storage/6
For supported configurations, refer to:
https://access.redhat.com/articles/1548993 https://access.redhat.com/errata/RHSA-2024:2633
Workarounds / mitigations:
Affected packages:
github.com/grafana/grafana >= 8.5.0, < 9.5.7github.com/grafana/grafana >= 10.0.0, < 10.0.12github.com/grafana/grafana >= 10.1.0, < 10.1.8github.com/grafana/grafana >= 10.2.0, < 10.2.5github.com/grafana/grafana >= 10.3.0, < 10.3.4Patched in:
github.com/grafana/grafana 9.5.7github.com/grafana/grafana 10.0.12github.com/grafana/grafana 10.1.8github.com/grafana/grafana 10.2.5github.com/grafana/grafana 10.3.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-80110High· 8.1A flaw was found in pki-core
CVE-2026-75939High· 7.4A flaw was found in openshift/oc-mirror
CVE-2026-94184High· 8.1A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support
CVE-2026-94368High· 7.1A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multicloud Object Gateway
CVE-2026-92574High· 8.8A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context
CVE-2026-15801High· 8.0A vulnerability was found in CRI-O related to the container checkpoint and restore feature