Grafana
- Total products in the ecosystem
- 32
- Total vulnerabilities (90 days)
- 24
en
Verify to analyze this security profile
As of 10/06/2026, Grafana recorded 24 security vulnerabilities in the last 90 days across 12 products, including 10 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, Grafana OSS had the most security vulnerabilities in the Grafana ecosystem, with 16 vulnerabilities—approximately 66.67% of the provider's total vulnerabilities during this period.
| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-89039Arbitrary file read via the convert_playwright_script prompt in mcp-k6 | Exploitation statusNot known exploited | FixYes | Affected productmcp-k6 | Published10/05/2026 | SeverityMedium |
CVE-2026-13720Editor can forge file-provisioning provenance on dashboards via the dashboard API | Exploitation statusNot known exploited | FixYes | Affected productGrafana OSS | Published09/30/2026 | SeverityMedium |
CVE-2026-13719Alert rules in restricted folders disclosed via the alert rules list API | Exploitation statusNot known exploited | FixYes | Affected productGrafana Enterprise | Published09/30/2026 | SeverityMedium |
CVE-2026-81842Library panel can be moved into a folder without library panel create permission | Exploitation statusNot known exploited | FixYes | Affected productGrafana Enterprise | Published09/29/2026 | SeverityMedium |
CVE-2026-81841Paused shared dashboard access tokens still expose data source configuration | Exploitation statusNot known exploited | FixYes | Affected productGrafana Enterprise | Published09/29/2026 | SeverityMedium |
CVE-2026-15815CVE-2026-15815 CVE Record | Exploitation statusNot known exploited | FixYes | Affected productGrafana OSS | Published09/17/2026 | SeverityHigh |
CVE-2026-76154CVE-2026-76154 CVE Record | Exploitation statusNot known exploited | FixYes | Affected productGrafana OSS | Published09/17/2026 | SeverityHigh |
CVE-2026-14199Session takeover via Auth Proxy cache key collision | Exploitation statusNot known exploited | FixYes | Affected productGrafana Enterprise | Published09/02/2026 | SeverityHigh |
CVE-2026-12704SAML assertion replay via skipped InResponseTo validation | Exploitation statusNot known exploited | FixYes | Affected productGrafana Enterprise | Published09/02/2026 | SeverityMedium |
CVE-2026-19475SQL Data Source Plugin: OOM DoS via $__timeGroup macro | Exploitation statusNot known exploited | FixYes | Affected productPostgreSQL Datasource | Published09/02/2026 | SeverityMedium |
CVE-2026-75889CVE-2026-75889 CVE Record | Exploitation statusNot known exploited | FixYes | Affected productAlloy | Published08/27/2026 | SeverityHigh |
CVE-2026-19854CVE-2026-19854 CVE Record | Exploitation statusNot known exploited | FixYes | Affected productClickhouse Datasource | Published08/27/2026 | SeverityMedium |
CVE-2026-19197Broken access control in dashboard snapshots | Exploitation statusNot known exploited | FixYes | Affected productGrafana OSS | Published08/26/2026 | SeverityMedium |
CVE-2026-17033CVE-2026-17033 CVE Record | Exploitation statusNot known exploited | FixYes | Affected productGrafana OSS | Published08/24/2026 | SeverityMedium |
CVE-2026-17183CVE-2026-17183 CVE Record | Exploitation statusNot known exploited | FixYes | Affected productGrafana OSS | Published08/19/2026 | SeverityHigh |
CVE-2026-11817CVE-2026-11817 CVE Record | Exploitation statusNot known exploited | FixYes | Affected productGrafana OSS | Published08/17/2026 | SeverityMedium |
CVE-2026-19516CVE-2026-19516 CVE Record | Exploitation statusNot known exploited | FixYes | Affected productGrafana MCP Server | Published08/11/2026 | SeverityCritical |
CVE-2026-9765CVE-2026-9765 CVE Record | Exploitation statusNot known exploited | FixYes | Affected productGrafana IRM | Published07/24/2026 | SeverityHigh |
CVE-2026-21723CVE-2026-21723 Record | Exploitation statusNot known exploited | FixYes | Affected productGrafana OSS | Published07/23/2026 | SeverityMedium |
CVE-2026-21729Loki detected_fields query limits results in unbounded memory allocation | Exploitation statusNot known exploited | FixYes | Affected productLoki | Published07/16/2026 | SeverityHigh |
CVE-2026-15583SSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL header | Exploitation statusNot known exploited | FixYes | Affected productGrafana MCP Server | Published07/15/2026 | SeverityHigh |
CVE-2026-8595Stored XSS in the table panel (TableNG) | Exploitation statusNot known exploited | FixYes | Affected productGrafana OSS | Published07/10/2026 | SeverityMedium |
CVE-2026-8609Pre-authentication denial of service via the OAuth login route | Exploitation statusNot known exploited | FixYes | Affected productGrafana OSS | Published07/10/2026 | SeverityMedium |
CVE-2026-33382Denial of service via unbounded request body size | Exploitation statusNot known exploited | FixYes | Affected productGrafana OSS | Published07/10/2026 | SeverityHigh |
CVE-2026-28378Cross-Organization Public Dashboard Deletion via Missing Org Isolation | Exploitation statusNot known exploited | FixYes | Affected productGrafana Enterprise | Published07/07/2026 | SeverityLow |
CVE-2026-42127Pre-authentication denial of service in the public dashboard query endpoint | Exploitation statusNot known exploited | FixYes | Affected productGrafana Enterprise | Published06/22/2026 | SeverityHigh |
CVE-2026-28381Local File Read/Write to Potential Privilege Escalation via Snowflake GET/PUT | Exploitation statusNot known exploited | FixYes | Affected productSnowflake Datasource | Published06/22/2026 | SeverityCritical |
CVE-2026-9029Stored XSS in the Geomap panel tile-layer attribution | Exploitation statusNot known exploited | FixYes | Affected productGrafana OSS | Published06/22/2026 | SeverityHigh |
CVE-2026-10601Path traversal in the Tempo and Loki data source plugins | Exploitation statusNot known exploited | FixYes | Affected productGrafana OSS | Published06/22/2026 | SeverityMedium |
CVE-2026-42129Path traversal in the Loki data source plugin | Exploitation statusNot known exploited | FixYes | Affected productGrafana OSS | Published06/22/2026 | SeverityHigh |
CVE-2026-27878Tempo TraceQL query with exemplar hint could result in unbounded memory usage | Exploitation statusNot known exploited | FixYes | Affected productEnterprise Traces (GET) | Published06/19/2026 | SeverityMedium |
CVE-2026-11769Operator - Namespaced User Path Traversal | Exploitation statusNot known exploited | FixYes | Affected productGrafana Operator | Published06/13/2026 | SeverityMedium |
CVE-2026-28374IDOR in Annotations API allows unprivileged users to DELETE annotation | Exploitation statusNot known exploited | FixYes | Affected productGrafana OSS | Published05/13/2026 | SeverityMedium |
CVE-2026-33378Grafana Data Source Plugin: DoS (OOM) via Negative Interval Injection in $__timeGroup Macro | Exploitation statusNot known exploited | FixYes | Affected productGrafana OSS | Published05/13/2026 | SeverityMedium |
CVE-2026-28383Grafana plugin resources can lead to unbounded memory allocation | Exploitation statusNot known exploited | FixYes | Affected productGrafana OSS | Published05/13/2026 | SeverityMedium |
CVE-2026-33376Auth Proxy IPv6 whitelist bypass | Exploitation statusNot known exploited | FixYes | Affected productGrafana OSS | Published05/13/2026 | SeverityHigh |
CVE-2026-33380SQL Expressions Read File From Disk | Exploitation statusNot known exploited | FixYes | Affected productGrafana OSS | Published05/13/2026 | SeverityMedium |
CVE-2026-28380BAC in Snapshot API allows deletion of unauthorized dashboard snapshots | Exploitation statusNot known exploited | FixYes | Affected productGrafana OSS | Published05/13/2026 | SeverityMedium |
CVE-2026-33381Users can generate Service Account tokens after permissions removal | Exploitation statusNot known exploited | FixYes | Affected productGrafana OSS | Published05/13/2026 | SeverityMedium |
CVE-2026-33377Dashboard Import Overwrites ACL — Editor Privilege Escalation to Dashboard Admin | Exploitation statusNot known exploited | FixYes | Affected productGrafana OSS | Published05/13/2026 | SeverityHigh |
CVE-2026-28376Grafana Live push endpoint allows unbounded memory allocation leading to OOM | Exploitation statusNot known exploited | FixYes | Affected productGrafana OSS | Published05/13/2026 | SeverityMedium |
CVE-2026-28379Viewer-triggered race condition in Grafana Live leads to complete server crash | Exploitation statusNot known exploited | FixYes | Affected productGrafana OSS | Published05/13/2026 | SeverityMedium |
CVE-2026-21728Tempo query limit results in unbounded memory allocation | Exploitation statusNot known exploited | FixYes | Affected productTempo | Published04/24/2026 | SeverityHigh |
CVE-2026-21726Loki Path Traversal - CVE-2021-36156 Bypass | Exploitation statusNot known exploited | FixYes | Affected productLoki | Published04/15/2026 | SeverityMedium |
CVE-2025-41118Sensitive COS `SecretKey` exposed in plaintext via configuration API due to missing type protection | Exploitation statusNot known exploited | FixYes | Affected productPyroscope | Published04/15/2026 | SeverityCritical |
CVE-2026-21727Grafana Correlations: Cross-Tenant Data Disclosure and Permanent Deletion via Legacy org_id=0 Record | Exploitation statusNot known exploited | FixYes | Affected productGrafana Correlations | Published04/15/2026 | SeverityLow |
CVE-2025-12141Grafana Alerting Editors can edit destination of webhooks they did not create | Exploitation statusNot known exploited | FixYes | Affected productGrafana Alerting | Published04/15/2026 | SeverityLow |
CVE-2026-27879Query resampling can cause unbounded memory allocations | Exploitation statusNot known exploited | FixYes | Affected productgrafana | Published03/27/2026 | SeverityMedium |
CVE-2026-28375Grafana Testdata datasource can issue unbounded memory allocations | Exploitation statusNot known exploited | FixYes | Affected productgrafana | Published03/27/2026 | SeverityMedium |
CVE-2026-27876RCE on Grafana via sqlExpressions | Exploitation statusNot known exploited | FixYes | Affected productgrafana | Published03/27/2026 | SeverityCritical |
CVE-2026-27880OpenFeature evaluation API reads input data with no bounds | Exploitation statusNot known exploited | FixYes | Affected productgrafana | Published03/27/2026 | SeverityHigh |
CVE-2026-27877Public dashboards discloses all direct mode datasources | Exploitation statusNot known exploited | FixYes | Affected productgrafana | Published03/27/2026 | SeverityHigh |
CVE-2026-28377S3 SSE-C Encryption Key Exposed in Plaintext via Config Endpoint (CVE-2025-41118 Pattern) | Exploitation statusNot known exploited | FixNot confirmed | Affected productTempo | Published03/26/2026 | SeverityHigh |
CVE-2026-21724Missing Protected-field Authorization in Provisioning Contact Points API | Exploitation statusNot known exploited | FixYes | Affected productGrafana OSS | Published03/26/2026 | SeverityMedium |
CVE-2026-33375Grafana MSSQL Data Source Plugin: Restriction Bypass Leading to OOM DoS | Exploitation statusNot known exploited | FixYes | Affected productGrafana OSS | Published03/26/2026 | SeverityMedium |
CVE-2026-21725Authorization Bypass via TOCTOU in Grafana Datasource Deletion by Name | Exploitation statusNot known exploited | FixYes | Affected productgrafana | Published02/25/2026 | SeverityLow |
CVE-2025-41117XSS in Grafana Explore stack trace | Exploitation statusNot known exploited | FixYes | Affected productgrafana/grafana | Published02/12/2026 | SeverityMedium |
CVE-2026-21722Public Dashboards time range restriction on annotations can be bypassed | Exploitation statusNot known exploited | FixYes | Affected productgrafana/grafana | Published02/12/2026 | SeverityMedium |
CVE-2026-21721Dashboard Permissions Scope Bypass Enables Cross‑Dashboard Privilege Escalation | Exploitation statusNot known exploited | FixYes | Affected productgrafana/grafana | Published01/27/2026 | SeverityHigh |
CVE-2026-21720Unauthenticated DoS: avatar cache leaks goroutines when /avatar/:hash requests time out | Exploitation statusNot known exploited | FixYes | Affected productgrafana/grafana-enterprise | Published01/27/2026 | SeverityHigh |
CVE-2025-41115Incorrect privilege assignment | Exploitation statusNot known exploited | FixYes | Affected productGrafana Enterprise | Published11/21/2025 | SeverityCritical |
CVE-2025-11539Arbitrary Code Execution in Grafana Image Renderer Plugin | Exploitation statusNot known exploited | FixYes | Affected productgrafana-image-renderer | Published10/09/2025 | SeverityCritical |
CVE-2025-10630Regex DoS in Grafana Zabbix Plugin | Exploitation statusNot known exploited | FixYes | Affected productgrafana-zabbix-plugin | Published09/19/2025 | SeverityMedium |
CVE-2025-8341SSRF in Infinity Datasource Plugin | Exploitation statusNot known exploited | FixYes | Affected productgrafana-infinity-datasource | Published08/04/2025 | SeverityMedium |
CVE-2025-6197 | Exploitation statusNot known exploited | FixYes | Affected productgrafana | Published07/18/2025 | SeverityMedium |
CVE-2025-6023 | Exploitation statusNot known exploited | FixYes | Affected productgrafana | Published07/18/2025 | SeverityHigh |
CVE-2025-3415 | Exploitation statusNot known exploited | FixYes | Affected productgrafana | Published07/17/2025 | SeverityMedium |
CVE-2025-1088Very long unicode dashboard title or panel name can hang the frontend | Exploitation statusNot known exploited | FixYes | Affected productgrafana | Published06/18/2025 | SeverityLow |
CVE-2025-3454 | Exploitation statusNot known exploited | FixYes | Affected productgrafana | Published06/02/2025 | SeverityMedium |
CVE-2025-3260 | Exploitation statusNot known exploited | FixYes | Affected productgrafana | Published06/02/2025 | SeverityHigh |
CVE-2025-3580 | Exploitation statusNot known exploited | FixYes | Affected productgrafana | Published05/23/2025 | SeverityMedium |
CVE-2025-4123 | Exploitation statusNot known exploited | FixYes | Affected productgrafana | Published05/22/2025 | SeverityHigh |
CVE-2025-2703 | Exploitation statusNot known exploited | FixYes | Affected productgrafana | Published04/23/2025 | SeverityMedium |
CVE-2024-11741 | Exploitation statusNot known exploited | FixYes | Affected productgrafana | Published01/31/2025 | SeverityMedium |
CVE-2024-10452 | Exploitation statusNot known exploited | FixNot confirmed | Affected productgrafana | Published10/29/2024 | SeverityLow |
CVE-2024-9264Grafana SQL Expressions allow for remote code execution | Exploitation statusPublic exploit | FixYes | Affected productgrafana | Published10/18/2024 | SeverityCritical |
CVE-2024-8118Grafana alerting wrong permission on datasource rule write endpoint | Exploitation statusNot known exploited | FixYes | Affected productgrafana | Published09/26/2024 | SeverityMedium |
CVE-2024-8996Grafana Agent Flow on Windows Unquoted service path | Exploitation statusNot known exploited | FixYes | Affected productAgent Flow | Published09/25/2024 | SeverityHigh |
CVE-2024-8975Grafana Alloy on Windows Unquoted service path | Exploitation statusNot known exploited | FixYes | Affected productAlloy | Published09/25/2024 | SeverityHigh |
CVE-2024-6322 | Exploitation statusNot known exploited | FixYes | Affected productgrafana | Published08/20/2024 | SeverityMedium |
CVE-2024-5526 | Exploitation statusNot known exploited | FixYes | Affected productOnCall | Published06/05/2024 | SeverityHigh |
CVE-2024-1313Users outside an organization can delete a snapshot with its key | Exploitation statusNot known exploited | FixYes | Affected productgrafana | Published03/26/2024 | SeverityMedium |
CVE-2024-1442User with permissions to create a data source can CRUD all data sources | Exploitation statusNot known exploited | FixYes | Affected productgrafana | Published03/07/2024 | SeverityMedium |
CVE-2023-5122SSRF in CSV Datasource Plugin | Exploitation statusNot known exploited | FixYes | Affected productgrafana-csv-datasource | Published02/14/2024 | SeverityMedium |
CVE-2023-5123Improper Path Sanitization in JSON Datasource Plugin | Exploitation statusNot known exploited | FixYes | Affected productgrafana-json-datasource | Published02/14/2024 | SeverityHigh |
CVE-2023-6152 | Exploitation statusPublic exploit | FixYes | Affected productgrafana | Published02/13/2024 | SeverityMedium |
CVE-2023-3010 | Exploitation statusNot known exploited | FixYes | Affected productworldmap-panel | Published10/25/2023 | SeverityHigh |
CVE-2023-4399 | Exploitation statusNot known exploited | FixYes | Affected productGrafana Enterprise | Published10/17/2023 | SeverityMedium |
CVE-2023-4457 | Exploitation statusNot known exploited | FixYes | Affected productgoogle-sheets-datasource | Published10/16/2023 | SeverityMedium |
CVE-2023-4822 | Exploitation statusNot known exploited | FixYes | Affected productGrafana Enterprise | Published10/16/2023 | SeverityMedium |
CVE-2023-3128 | Exploitation statusPublic exploit | FixYes | Affected productgrafana | Published06/22/2023 | SeverityCritical |
CVE-2023-2183 | Exploitation statusPublic exploit | FixYes | Affected productgrafana | Published06/06/2023 | SeverityMedium |
CVE-2023-2801 | Exploitation statusNot known exploited | FixYes | Affected productgrafana | Published06/06/2023 | SeverityHigh |
CVE-2023-1387 | Exploitation statusPublic exploit | FixYes | Affected productgrafana | Published04/26/2023 | SeverityMedium |
CVE-2023-1410Stored XSS in Graphite FunctionDescription tooltip | Exploitation statusPublic exploit | FixYes | Affected productgrafana | Published03/23/2023 | SeverityMedium |
CVE-2023-22462Stored XSS in Grafana Text plugin | Exploitation statusNot known exploited | FixYes | Affected productgrafana | Published03/02/2023 | SeverityMedium |
CVE-2023-0594 | Exploitation statusNot known exploited | FixYes | Affected productgrafana | Published03/01/2023 | SeverityHigh |
CVE-2023-0507 | Exploitation statusNot known exploited | FixYes | Affected productgrafana | Published03/01/2023 | SeverityHigh |
CVE-2022-23498When query caching is enabled in Grafana users can query another users session | Exploitation statusNot known exploited | FixYes | Affected productgrafana | Published02/03/2023 | SeverityHigh |
CVE-2022-23552Grafana stored XSS in FileUploader component | Exploitation statusNot known exploited | FixNot confirmed | Affected productgrafana | Published01/27/2023 | SeverityHigh |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan