---
id: CVE-2026-42129
title: >-
  A user with Viewer permissions can use a path traversal in the Loki data
  source plugin to reach administrative Loki endpoints and read sensitive
  backend configuration and internal service information.
summary: >-
  A user with Viewer permissions can use a path traversal in the Loki data
  source plugin to reach administrative Loki endpoints and read sensitive
  backend configuration and internal service information.
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-22
vendor: grafana
product: loki_datasource
affected:
  - loki_datasource
published: '2026-06-22'
updated: '2026-07-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-42129'
references:
  - url: 'https://grafana.com/security/security-advisories/cve-2026-42129'
    label: security@grafana.com
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-42129'
  - url: >-
      https://github.com/grafana/grafana/commit/3fcdbc5a6e5c955bd42bd3715dd03cbad2b078c1
  - url: >-
      https://github.com/grafana/grafana/commit/42cdc39124912a8506a0c613c319c345aa950b29
  - url: >-
      https://github.com/grafana/grafana/commit/82ef13993059351bf21de35b8488bbd9b42df4f4
  - url: >-
      https://github.com/grafana/grafana/commit/d27d2eba9c509d16f214d290436a6ad0bd9c6c01
  - url: >-
      https://github.com/grafana/grafana/commit/dd5dc51681ff0133ddb2e206c2ea318713aeca16
  - url: >-
      https://github.com/grafana/grafana/commit/eeb08ceb020c4381242d8400e5878044e9877505
  - url: >-
      https://github.com/grafana/grafana/commit/f70d3e480274a5dbd12006338c393f4b05d441ca
  - url: 'https://github.com/grafana/grafana/releases/tag/v11.6.15'
  - url: 'https://github.com/grafana/grafana/releases/tag/v12.2.9'
  - url: 'https://github.com/grafana/grafana/releases/tag/v12.3.7'
  - url: 'https://github.com/grafana/grafana/releases/tag/v12.4.4'
  - url: 'https://github.com/grafana/grafana/releases/tag/v13.0.2'
  - url: 'https://github.com/advisories/GHSA-f74p-cwhp-x2wx'
  - url: 'https://github.com/grafana/grafana'
tags:
  - nvd
  - ghsa
  - go
  - osv
epss: 0.00443
epssPercentile: 0.35861
ingestedAt: '2026-07-11T13:13:24.678Z'
aliases:
  - GHSA-f74p-cwhp-x2wx
ecosystem: go
patched:
  - github.com/grafana/grafana 1.9.2-0.20260616075434-82ef13993059
---

## Overview

A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.

## Affected

- `loki_datasource`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-42129)

Affected packages:

- `github.com/grafana/grafana >= 2.0.0-beta1, < 11.6.15`
- `github.com/grafana/grafana >= 12.0.0, < 12.2.9`
- `github.com/grafana/grafana >= 12.3.0, < 12.3.7`
- `github.com/grafana/grafana >= 13.0.0, < 13.0.2`
- `github.com/grafana/grafana >= 12.4.0, < 12.4.4`
- `github.com/grafana/grafana < 1.9.2-0.20260616075434-82ef13993059`

Patched in:

- `github.com/grafana/grafana 1.9.2-0.20260616075434-82ef13993059`

Source: https://github.com/advisories/GHSA-f74p-cwhp-x2wx
