Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-15815— CVE-2026-15815 CVE Record

Quick assessment

Affected
Grafana Grafana OSS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Grafana OSS 和 Grafana Enterprise 在解压缩插件压缩包时,未能安全地处理符号链接。攻击者可以构造一个特制的插件压缩包,通过链接相对符号链接条目,使文件写入逃逸出插件安装目录,从而在目录外部写入任意文件以及可执行的后端二进制文件。被释放的可执行文件将以 Grafana 服务器进程的权限运行,进而导致远程代码执行(RCE)。 由于插件压缩包在签名验证之前就会被解压,因此有效的插件签名无法阻止这种文件写入。因此,运维人员可能通过安装看似合法的插件,或者通过 、 环境变量或预安装配置,从任意压

CVSS 8.8 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-15815

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
CVE-2026-15815 CVE Record
Source: CVE Program / CVE List V5
Vulnerability Description
Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, writing arbitrary files and an executable backend binary outside that directory. The dropped executable runs with the privileges of the Grafana server process, resulting in remote code execution. Plugin archives are extracted before their signature is verified, so a valid plugin signature does not prevent the write. An operator can therefore be affected by installing a plugin that appears legitimate, as well as by installing a plugin from an arbitrary archive using grafana-cli, the GF_INSTALL_PLUGINS environment variable, or preinstall configuration. Grafana Enterprise is affected because it includes the same plugin extraction code as Grafana OSS.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
在文件访问前对链接解析不恰当(链接跟随)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Grafana Grafana OSS 11.6.0 ~ 11.6.17 -
Grafana Grafana Enterprise 11.6.0 ~ 11.6.17 -

II. Public POCs for CVE-2026-15815

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-15815

登录查看更多情报信息。

Vendor Advisories for CVE-2026-15815 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-15815

No comments yet


Leave a comment