VulnSea

grafana vulnerabilities

CVEs whose affected-version data names the grafana package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

7 CVEsRSS

CVE-2026-14199High· 7.1
2w ago

Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected

Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a del…

Twilightgrafana · grafanaEPSS 0.31%via NVD
CVE-2026-42127High· 7.5
3mo ago

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of serv…

Twilightgrafana · grafanaEPSS 0.43%via NVD
CVE-2026-9029High· 7.3
3mo ago

A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable

A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored…

Twilightgrafana · grafanaEPSS 0.25%via NVD
CVE-2026-10601Medium· 5.4
3mo ago

A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints

A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak inter…

Sunlitgrafana · grafanaEPSS 0.29%via NVD
CVE-2026-21727Low· 3.3
5mo ago

A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records

A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records. Due to a backward compatibility condition allowing org_id = 0 records to be returned across organizations, a user wi…

Sunlitgrafana · grafanaEPSS 0.20%via NVD
CVE-2026-21721High· 8.1PoC
7mo ago

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on ot…

Midnightgrafana · grafanaEPSS 0.69%via NVD
CVE-2026-21720High· 7.5
7mo ago

Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image

Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer than three seconds, the handler times out and stops listening for the result, so that gorou…

Twilightgrafana · grafanaEPSS 0.66%via NVD
grafana vulnerabilities (CVEs) · VulnSea