Grafana OSS
8 known vulnerabilities in Grafana OSS, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-13720 CVSS 5.4 medium An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations)…
- CVE-2026-13719 CVSS 4.3 medium An authenticated user can list alert rules stored in folders they are not allowed to read through the alert rules API list endpoint. When…
- CVE-2026-81842 CVSS 4.3 medium An authenticated user with edit permission on one folder can move a library panel into another folder where they only have view…
- CVE-2026-81841 CVSS 5.3 medium Pausing a shared (public) dashboard did not revoke its access token for the endpoints that serve frontend bootstrap data. Anyone holding…
- CVE-2026-76154 CVSS 7.3 high A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute…
- CVE-2026-15815 CVSS 8.8 high Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can…
- CVE-2026-19475 CVSS 6.5 medium An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro…
- CVE-2026-14199 CVSS 8.1 high Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected…