CVE-2026-10601Medium· 5.4▾ SunlitA user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak inter…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
0.3% → 0.3%
A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative actions on the configured backend.
grafana = 11.6.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/grafana/grafana >= 2.0.0-beta1, < 11.6.15github.com/grafana/grafana >= 12.0.0, < 12.2.9github.com/grafana/grafana >= 12.3.0, < 12.3.7github.com/grafana/grafana >= 13.0.0, < 13.0.2github.com/grafana/grafana >= 12.4.0, < 12.4.4github.com/grafana/grafana < 1.9.2-0.20260616075434-82ef13993059Patched in:
github.com/grafana/grafana 1.9.2-0.20260616075434-82ef13993059Connected by shared product, vendor, weakness, or advisory.
CVE-2026-42127High· 7.5The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads
CVE-2026-9029High· 7.3A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable
CVE-2026-42129High· 7.7A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.
CVE-2026-14199High· 7.1Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected
CVE-2023-22462Medium· 6.4Grafana vulnerable to Stored Cross-site Scripting in Text plugin
CVE-2020-13430Medium· 6.1Grafana XSS via the OpenTSDB datasource