VulnSea

grafana has 38 CVEs on record between 2021 and 2026. Disclosures have slowed: 4 in the last 90 days after 13 in the 90 before. The busiest recent month was June 2026 with 7. The median CVSS is 6.5 (medium), with 3 rated critical. 5% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-22 (5) and CWE-400 (3). Most affected products: github.com/grafana/grafana (18), grafana (7), Grafana OSS (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
5% vs 1% corpus
Median CVSS
6.5
Publish → KEV
(2)
Last 90 days
4 prev 13

Products

  • github.com/grafana/grafana 18
  • grafana 7
  • Grafana OSS 3
  • github.com/grafana/tempo 2
  • github.com/grafana/agent 1
  • github.com/grafana/grafana-operator 1
38
Total CVEs
3
Critical
2
CISA KEV
2
Exploited

grafana vulnerabilities

CVEs affecting grafana, newest first. Open any entry for full detail, references, and exploit status.

38 CVEsRSS

CVE-2026-76154High· 7.3
5d ago

A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user's session by hosting a malicious style configuration, enabling escal…

A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user's session by hosting a malicious style configuration, enabling escal…

TwilightGrafana · Grafana OSSEPSS 0.39%via NVD
CVE-2026-15815High· 8.8
5d ago

Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives

Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, writing arbitrary fi…

TwilightGrafana · Grafana OSSEPSS 0.87%via NVD
CVE-2026-14199High· 7.1
2w ago

Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected

Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a del…

Twilightgrafana · grafanaEPSS 0.31%via NVD
CVE-2026-11817Medium· 5.3
1mo ago

CVE-2026-11817 CVE Record

This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted. In a multi-organization stack, a user who is an Org Admin of a single organization can call GET /api…

SunlitGrafana · Grafana OSSEPSS 0.26%via CVEORG
CVE-2026-42127High· 7.5
3mo ago

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of serv…

Twilightgrafana · grafanaEPSS 0.43%via NVD
CVE-2026-9029High· 7.3
3mo ago

A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable

A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored…

Twilightgrafana · grafanaEPSS 0.25%via NVD
CVE-2026-42129High· 7.7
3mo ago

A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.

A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.

Twilightgrafana · loki_datasourceEPSS 0.44%via NVD
CVE-2026-10601Medium· 5.4
3mo ago

A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints

A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak inter…

Sunlitgrafana · grafanaEPSS 0.29%via NVD
CVE-2026-27878Medium· 6.5
3mo ago

Grafana Tempo vulnerable to an out-of-memory crash

Grafana Tempo vulnerable to an out-of-memory crash

Sunlitgrafana · github.com/grafana/tempoEPSS 0.41%via OSV
CVE-2026-11769Medium
3mo ago

Grafana Operator: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileName

Grafana Operator: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileName

Sunlitgrafana · github.com/grafana/grafana-operator/v5EPSS 0.36%via GHSA
GHSA-v82c-5c2q-hx9gMedium
3mo ago

Duplicate Advisory: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileName

Duplicate Advisory: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileName

Sunlitgrafana · github.com/grafana/grafana-operatorvia GHSA
CVE-2026-21728High· 7.5
5mo ago

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g. to …

Twilightgrafana · tempoEPSS 0.64%via NVD
CVE-2026-21727Low· 3.3
5mo ago

A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records

A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records. Due to a backward compatibility condition allowing org_id = 0 records to be returned across organizations, a user wi…

Sunlitgrafana · grafanaEPSS 0.20%via NVD
CVE-2025-41118Critical· 9.1
5mo ago

Pyroscope is an open-source continuous profiling database

Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (COS). If the database is configured to use Tencent COS as the storage backend, an attacke…

Midnightgrafana · pyroscopeEPSS 0.41%via NVD
CVE-2026-21726Medium· 5.3
5mo ago

Grafana Loki Path Traversal - CVE-2021-36156 Bypass

Grafana Loki Path Traversal - CVE-2021-36156 Bypass

Sunlitgrafana · github.com/grafana/loki/v3EPSS 0.41%via OSV
CVE-2026-27877Medium· 6.5
5mo ago

Grafana public dashboards disclose all direct mode datasources

Grafana public dashboards disclose all direct mode datasources

Sunlitgrafana · github.com/grafana/grafanaEPSS 0.31%via OSV
CVE-2026-28377High· 7.5
5mo ago

Grafana Tempo has Inadequate Encryption Strength

Grafana Tempo has Inadequate Encryption Strength

Twilightgrafana · github.com/grafana/tempoEPSS 0.15%via OSV
CVE-2026-21724Medium· 5.4
6mo ago

Grafana OSS: Authorization bypass allows users with Editor role to modify protected webhook URLs without permissions

Grafana OSS: Authorization bypass allows users with Editor role to modify protected webhook URLs without permissions

Sunlitgrafana · github.com/grafana/grafanaEPSS 0.26%via OSV
CVE-2026-21721High· 8.1PoC
7mo ago

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on ot…

Midnightgrafana · grafanaEPSS 0.69%via NVD
CVE-2026-21720High· 7.5
7mo ago

Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image

Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer than three seconds, the handler times out and stops listening for the result, so that gorou…

Twilightgrafana · grafanaEPSS 0.66%via NVD
CVE-2025-3415Medium· 4.3PoC
1y ago

Grafana's insecure DingDing Alert integration exposes sensitive information

Grafana's insecure DingDing Alert integration exposes sensitive information

Twilightgrafana · github.com/grafana/grafanaEPSS 0.98%via OSV
CVE-2025-3260High· 8.3
1y ago

Grafana vulnerable to authenticated users bypassing dashboard, folder permissions

Grafana vulnerable to authenticated users bypassing dashboard, folder permissions

Twilightgrafana · github.com/grafana/grafanaEPSS 0.56%via OSV
CVE-2024-10452Low· 2.2
1y ago

Grafana org admin can delete pending invites in different org

Grafana org admin can delete pending invites in different org

Sunlitgrafana · github.com/grafana/grafanaEPSS 0.49%via OSV
CVE-2021-41244Critical· 9.1
2y ago

Grafana Fine-grained access control vulnerability

Grafana Fine-grained access control vulnerability

Midnightgrafana · github.com/grafana/grafanaEPSS 2.9%via OSV
CVE-2021-43815Medium· 4.3
2y ago

Grafana directory traversal for .cvs files

Grafana directory traversal for .cvs files

Sunlitgrafana · github.com/grafana/grafanaEPSS 1.8%via OSV
CVE-2023-6152Medium· 5.4
2y ago

Email Validation Bypass And Preventing Sign Up From Email's Owner

Email Validation Bypass And Preventing Sign Up From Email's Owner

Sunlitgrafana · github.com/grafana/grafanaEPSS 1.4%via OSV
CVE-2021-43798High· 7.5CISA KEVPoC
2y ago

Grafana path traversal

Grafana path traversal

Abyssalgrafana · github.com/grafana/grafanaEPSS 89%via OSV
CVE-2019-19499Medium· 6.5
2y ago

Grafana Arbitrary File Read

Grafana Arbitrary File Read

Sunlitgrafana · github.com/grafana/grafanaEPSS 3.6%via OSV
CVE-2023-3128Critical· 9.4PoC
3y ago

Grafana vulnerable to Authentication Bypass by Spoofing

Grafana vulnerable to Authentication Bypass by Spoofing

Abyssalgrafana · github.com/grafana/grafanaEPSS 4.0%via OSV
CVE-2023-2183Medium· 4.1
3y ago

Grafana has Broken Access Control in Alert manager: Viewer can send test alerts

Grafana has Broken Access Control in Alert manager: Viewer can send test alerts

Sunlitgrafana · github.com/grafana/grafanaEPSS 1.0%via OSV
grafana vulnerabilities (CVEs) · VulnSea