---
id: CVE-2026-10601
title: >-
  A user with Viewer permissions can use specially crafted requests to the Tempo
  and Loki data source plugins to reach unintended backend endpoints
summary: >-
  A user with Viewer permissions can use specially crafted requests to the Tempo
  and Loki data source plugins to reach unintended backend endpoints. Depending
  on the backend configuration this can expose data source credentials, leak
  inter…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-22
vendor: grafana
product: grafana
affected:
  - grafana = 11.6.0
published: '2026-06-22'
updated: '2026-07-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-10601'
references:
  - url: 'https://grafana.com/security/security-advisories/cve-2026-10601'
    label: security@grafana.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-10601.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-10601'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2491359'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-10601'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-10601'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68143'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67573'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67605'
  - url: 'https://access.redhat.com/errata/RHSA-2026:64525'
  - url: 'https://access.redhat.com/errata/RHSA-2026:64585'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62527'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62537'
  - url: 'https://github.com/grafana/grafana/pull/125789'
  - url: >-
      https://github.com/grafana/grafana/commit/3fcdbc5a6e5c955bd42bd3715dd03cbad2b078c1
  - url: >-
      https://github.com/grafana/grafana/commit/42cdc39124912a8506a0c613c319c345aa950b29
  - url: >-
      https://github.com/grafana/grafana/commit/82ef13993059351bf21de35b8488bbd9b42df4f4
  - url: >-
      https://github.com/grafana/grafana/commit/d27d2eba9c509d16f214d290436a6ad0bd9c6c01
  - url: >-
      https://github.com/grafana/grafana/commit/dd5dc51681ff0133ddb2e206c2ea318713aeca16
  - url: >-
      https://github.com/grafana/grafana/commit/f70d3e480274a5dbd12006338c393f4b05d441ca
  - url: 'https://github.com/grafana/grafana/releases/tag/v11.6.15'
  - url: 'https://github.com/grafana/grafana/releases/tag/v12.2.9'
  - url: 'https://github.com/grafana/grafana/releases/tag/v12.3.7'
  - url: 'https://github.com/grafana/grafana/releases/tag/v12.4.4'
  - url: 'https://github.com/grafana/grafana/releases/tag/v13.0.2'
  - url: 'https://github.com/advisories/GHSA-9493-h4f5-633x'
  - url: 'https://github.com/grafana/grafana'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
  - ghsa
  - go
  - osv
epss: 0.00286
epssPercentile: 0.18727
ingestedAt: '2026-07-11T13:13:24.663Z'
patched:
  - hardened_images
aliases:
  - GHSA-9493-h4f5-633x
  - BIT-grafana-2026-10601
ecosystem: go
---

## Overview

A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative actions on the configured backend.

## Affected

- `grafana = 11.6.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Multicluster Global Hub, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Ceph Storage 5, Red Hat Ceph Storage 6, Red Hat Ceph Storage 7, Red Hat Ceph Storage 8, … · no fix planned: Multicluster Global Hub, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Ceph Storage 5, Red Hat Ceph Storage 6, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-10601.json)
- **RHSA-2026:68143** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:68143)
- **RHSA-2026:67573** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67573)
- **RHSA-2026:67605** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67605)
- **RHSA-2026:64525** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:64525)
- **RHSA-2026:64585** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:64585)
- **RHSA-2026:62527** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:62527)
- **RHSA-2026:62537** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:62537)

## Package advisory (CVE-2026-10601)

Affected packages:

- `github.com/grafana/grafana >= 2.0.0-beta1, < 11.6.15`
- `github.com/grafana/grafana >= 12.0.0, < 12.2.9`
- `github.com/grafana/grafana >= 12.3.0, < 12.3.7`
- `github.com/grafana/grafana >= 13.0.0, < 13.0.2`
- `github.com/grafana/grafana >= 12.4.0, < 12.4.4`
- `github.com/grafana/grafana < 1.9.2-0.20260616075434-82ef13993059`

Patched in:

- `github.com/grafana/grafana 1.9.2-0.20260616075434-82ef13993059`

Source: https://github.com/advisories/GHSA-9493-h4f5-633x
