Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

grafana — Vulnerabilities & Security Advisories 126

Browse all 126 CVE security advisories affecting grafana. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Grafana serves as a leading open-source platform for observability, enabling users to visualize metrics, logs, and traces from diverse data sources. Despite its utility, the software has accumulated 85 recorded Common Vulnerabilities and Exposures (CVEs), reflecting a history of security challenges. Historically, these flaws frequently involve remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from insufficient input validation or improper access controls in its plugin ecosystem and API endpoints. While no single catastrophic incident has defined its entire lifecycle, the high volume of CVEs indicates persistent risks in its complex architecture. Security teams must prioritize regular patching and strict configuration management to mitigate these known weaknesses, ensuring that the platform’s robust visualization capabilities do not compromise underlying infrastructure integrity.

CVE ID Title CVSS Severity Published
CVE-2026-13719 Alert rules in restricted folders disclosed via the alert rules list API — Grafana Enterprise CWE-863 4.3 Medium 2026-09-30
CVE-2026-13720 Editor can forge file-provisioning provenance on dashboards via the dashboard API — Grafana OSS CWE-285 5.4 Medium 2026-09-30
CVE-2026-81842 Library panel can be moved into a folder without library panel create permission — Grafana Enterprise CWE-863 4.3 Medium 2026-09-29
CVE-2026-81841 Paused shared dashboard access tokens still expose data source configuration — Grafana Enterprise CWE-862 5.3 Medium 2026-09-29
CVE-2026-15815 CVE-2026-15815 CVE Record — Grafana OSS CWE-59 8.8 High 2026-09-17
CVE-2026-76154 CVE-2026-76154 CVE Record — Grafana OSS CWE-79 7.3 High 2026-09-17
CVE-2026-14199 Session takeover via Auth Proxy cache key collision — Grafana Enterprise CWE-290 7.1 High 2026-09-02
CVE-2026-12704 SAML assertion replay via skipped InResponseTo validation — Grafana Enterprise CWE-294 6.8 Medium 2026-09-02
CVE-2026-19475 SQL Data Source Plugin: OOM DoS via $__timeGroup macro — PostgreSQL Datasource 6.5 Medium 2026-09-02
CVE-2026-75889 CVE-2026-75889 CVE Record — Alloy 7.7 High 2026-08-27
CVE-2026-19854 CVE-2026-19854 CVE Record — Clickhouse Datasource CWE-319 6.1 Medium 2026-08-27
CVE-2026-19197 Broken access control in dashboard snapshots — Grafana OSS CWE-862 6.3 Medium 2026-08-26
CVE-2026-17033 CVE-2026-17033 CVE Record — Grafana OSS CWE-79 6.8 Medium 2026-08-24
CVE-2026-17183 CVE-2026-17183 CVE Record — Grafana OSS CWE-863 7.1 High 2026-08-19
CVE-2026-11817 CVE-2026-11817 CVE Record — Grafana OSS CWE-863 5.3 Medium 2026-08-17
CVE-2026-19516 CVE-2026-19516 CVE Record — Grafana MCP Server CWE-918 9.1 Critical 2026-08-11
CVE-2026-9765 CVE-2026-9765 CVE Record — Grafana IRM 7.1 High 2026-07-24
CVE-2026-21723 CVE-2026-21723 Record — Grafana OSS 5.3 Medium 2026-07-23
CVE-2026-21729 Loki detected_fields query limits results in unbounded memory allocation — Loki 7.5 High 2026-07-16
CVE-2026-15583 SSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL header — Grafana MCP Server 8.6 High 2026-07-15
CVE-2026-8595 Stored XSS in the table panel (TableNG) — Grafana OSS CWE-79 6.8 Medium 2026-07-10
CVE-2026-8609 Pre-authentication denial of service via the OAuth login route — Grafana OSS CWE-400 5.3 Medium 2026-07-10
CVE-2026-33382 Denial of service via unbounded request body size — Grafana OSS CWE-400 7.5 High 2026-07-10
CVE-2026-28378 Cross-Organization Public Dashboard Deletion via Missing Org Isolation — Grafana Enterprise 3.1 Low 2026-07-07
CVE-2026-42127 Pre-authentication denial of service in the public dashboard query endpoint — Grafana Enterprise CWE-400 7.5 High 2026-06-22
CVE-2026-28381 Local File Read/Write to Potential Privilege Escalation via Snowflake GET/PUT — Snowflake Datasource 9.6 Critical 2026-06-22
CVE-2026-9029 Stored XSS in the Geomap panel tile-layer attribution — Grafana OSS CWE-79 7.3 High 2026-06-22
CVE-2026-10601 Path traversal in the Tempo and Loki data source plugins — Grafana OSS CWE-22 5.4 Medium 2026-06-22
CVE-2026-42129 Path traversal in the Loki data source plugin — Grafana OSS CWE-22 7.7 High 2026-06-22
CVE-2026-27878 Tempo TraceQL query with exemplar hint could result in unbounded memory usage — Enterprise Traces (GET) 6.5 Medium 2026-06-19

This page lists every published CVE security advisory associated with grafana. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.