Grafana — свободная программная система визуализации данных, ориентированная на данные систем ИТ-мониторинга.
Релизный цикл, информация об уязвимостях
График релизов
Количество 574
CVE-2026-10601
A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative actions on the configured backend.
CVE-2026-9029
A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).
CVE-2026-10601
A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative actions on the configured backend.
BDU:2026-10549
Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
GHSA-5cv7-h7gr-wjgh
An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.
GHSA-29p4-5443-x453
Any Editor could delete any snapshot, even if they have no access to read or write them.
GHSA-rr8q-qwrv-9pf6
Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-restart, the impact is minimal or non-existent, as the attack can take upwards of half an hour to crash the server.
GHSA-gxcp-jjxh-rwp4
Grafana: SQL Expressions Read File From Disk
GHSA-8mrj-8pc8-39jm
Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read the annotations.
GHSA-wfhv-mj62-f5xh
Grafana: Users can generate Service Account tokens after permissions removal
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2026-10601 A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative actions on the configured backend. | CVSS3: 5.4 | 0% Низкий | около 1 месяца назад | |
CVE-2026-9029 A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting). | CVSS3: 7.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-10601 A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative actions on the configured backend. | CVSS3: 5.4 | 0% Низкий | около 1 месяца назад | |
BDU:2026-10549 Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации | CVSS3: 4.3 | 0% Низкий | около 1 месяца назад | |
GHSA-5cv7-h7gr-wjgh An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege. | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
GHSA-29p4-5443-x453 Any Editor could delete any snapshot, even if they have no access to read or write them. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
GHSA-rr8q-qwrv-9pf6 Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-restart, the impact is minimal or non-existent, as the attack can take upwards of half an hour to crash the server. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
GHSA-gxcp-jjxh-rwp4 Grafana: SQL Expressions Read File From Disk | CVSS3: 6.3 | 0% Низкий | 3 месяца назад | |
GHSA-8mrj-8pc8-39jm Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read the annotations. | CVSS3: 4.3 | 0% Низкий | 3 месяца назад | |
GHSA-wfhv-mj62-f5xh Grafana: Users can generate Service Account tokens after permissions removal | CVSS3: 5.9 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу