Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-17183— CVE-2026-17183 CVE Record

Quick assessment

Affected
Grafana Grafana OSS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是该漏洞描述信息的中文翻译: 摘要 拥有创建或编辑文件夹中告警规则权限的组织用户,可以查询其不具备 (数据源查询)权限的数据源。攻击者将客户端可控的查询字段 设置为 ,同时保留真实数据源的 UID。 告警规则授权路径将查询视为服务器端表达式,从而绕过了数据源权限的强制执行。随后,评估器会根据由 标识的真实数据源解析并执行该查询。 影响 此绕过漏洞可让未被授权直接查询特定数据源的低权限用户,访问通过 Grafana 配置的数据源凭据可获取的数据。保密性影响为高。 完整性影响为低,因为部分数据源后端及配置的凭据可能

CVSS 7.1 · High EPSS 0.34% · P27

Possible ATT&CK Techniques 1 AI

T1078 · Valid Accounts

Affected Version Matrix 8

VendorProduct Version RangeStatus
Grafana Grafana Enterprise 8.4.0< 12.3.11 affected
12.4.0< 12.4.9 affected
13.0.0< 13.0.7 affected
13.1.0< 13.1.4 affected
Grafana Grafana OSS 8.4.0< 12.3.11 affected
12.4.0< 12.4.9 affected
13.0.0< 13.0.7 affected
13.1.0< 13.1.4 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-17183

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
CVE-2026-17183 CVE Record
Source: CVE Program / CVE List V5
Vulnerability Description
An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a server-side expression while referencing a real datasource UID (incorrect authorization). This can expose data accessible through Grafana's configured datasource credentials to users who lack permission to query that datasource.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Grafana Grafana OSS 8.4.0 ~ 12.3.11 -
Grafana Grafana Enterprise 8.4.0 ~ 12.3.11 -

II. Public POCs for CVE-2026-17183

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-17183

登录查看更多情报信息。

Vendor Advisories for CVE-2026-17183 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-17183

No comments yet


Leave a comment