Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Grafana

Grafanaсвободная программная система визуализации данных, ориентированная на данные систем ИТ-мониторинга.

Релизный цикл, информация об уязвимостях

Продукт: Grafana
Вендор: grafana

График релизов

12.312.413.013.12025202620272028

Недавние уязвимости Grafana

Количество 574

nvd логотип

CVE-2026-10601

около 1 месяца назад

A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative actions on the configured backend.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2026-9029

около 1 месяца назад

A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2026-10601

около 1 месяца назад

A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative actions on the configured backend.

CVSS3: 5.4
EPSS: Низкий
fstec логотип

BDU:2026-10549

около 1 месяца назад

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-5cv7-h7gr-wjgh

3 месяца назад

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-29p4-5443-x453

3 месяца назад

Any Editor could delete any snapshot, even if they have no access to read or write them.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-rr8q-qwrv-9pf6

3 месяца назад

Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-restart, the impact is minimal or non-existent, as the attack can take upwards of half an hour to crash the server.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-gxcp-jjxh-rwp4

3 месяца назад

Grafana: SQL Expressions Read File From Disk

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-8mrj-8pc8-39jm

3 месяца назад

Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read the annotations.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-wfhv-mj62-f5xh

3 месяца назад

Grafana: Users can generate Service Account tokens after permissions removal

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2026-10601

A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative actions on the configured backend.

CVSS3: 5.4
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-9029

A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).

CVSS3: 7.3
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-10601

A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative actions on the configured backend.

CVSS3: 5.4
0%
Низкий
около 1 месяца назад
fstec логотип
BDU:2026-10549

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 4.3
0%
Низкий
около 1 месяца назад
github логотип
GHSA-5cv7-h7gr-wjgh

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.

CVSS3: 7.1
0%
Низкий
3 месяца назад
github логотип
GHSA-29p4-5443-x453

Any Editor could delete any snapshot, even if they have no access to read or write them.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-rr8q-qwrv-9pf6

Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-restart, the impact is minimal or non-existent, as the attack can take upwards of half an hour to crash the server.

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-gxcp-jjxh-rwp4

Grafana: SQL Expressions Read File From Disk

CVSS3: 6.3
0%
Низкий
3 месяца назад
github логотип
GHSA-8mrj-8pc8-39jm

Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read the annotations.

CVSS3: 4.3
0%
Низкий
3 месяца назад
github логотип
GHSA-wfhv-mj62-f5xh

Grafana: Users can generate Service Account tokens after permissions removal

CVSS3: 5.9
0%
Низкий
3 месяца назад

Уязвимостей на страницу


Поделиться