CVE-2026-42129High· 7.7▾ TwilightA user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
0.4% → 0.4%
A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.
loki_datasourceRefer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/grafana/grafana >= 2.0.0-beta1, < 11.6.15github.com/grafana/grafana >= 12.0.0, < 12.2.9github.com/grafana/grafana >= 12.3.0, < 12.3.7github.com/grafana/grafana >= 13.0.0, < 13.0.2github.com/grafana/grafana >= 12.4.0, < 12.4.4github.com/grafana/grafana < 1.9.2-0.20260616075434-82ef13993059Patched in:
github.com/grafana/grafana 1.9.2-0.20260616075434-82ef13993059Connected by shared product, vendor, weakness, or advisory.
CVE-2026-10601Medium· 5.4A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints
CVE-2026-42127High· 7.5The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads
CVE-2026-9029High· 7.3A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable
CVE-2023-22462Medium· 6.4Grafana vulnerable to Stored Cross-site Scripting in Text plugin
CVE-2020-13430Medium· 6.1Grafana XSS via the OpenTSDB datasource
CVE-2024-10452Low· 2.2Grafana org admin can delete pending invites in different org