Grafana Vulnerabilities and Affected Products
Vulnerabilities associated with grafana.
Products
Clear product- grafana59 vulnerabilities
- Grafana OSS21 vulnerabilities
- Grafana Enterprise16 vulnerabilities
- grafana/grafana4 vulnerabilities
- grafana/grafana-enterprise4 vulnerabilities
- Tempo3 vulnerabilities
- Enterprise Traces (GET)2 vulnerabilities
- Grafana MCP Server2 vulnerabilities
- grafana-image-renderer2 vulnerabilities
- grafana_enterprise2 vulnerabilities
- Loki2 vulnerabilities
- agent1 vulnerability
- Agent Flow1 vulnerability
- agent_flow_windows1 vulnerability
- Alloy1 vulnerability
- google-sheets-datasource1 vulnerability
- Grafana Alerting1 vulnerability
- Grafana Correlations1 vulnerability
- Grafana IRM1 vulnerability
- Grafana Operator1 vulnerability
- grafana-csv-datasource1 vulnerability
- grafana-infinity-datasource1 vulnerability
- grafana-json-datasource1 vulnerability
- grafana-zabbix-plugin1 vulnerability
- mcp-grafana1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-27879MEDIUM | Query resampling can cause unbounded memory allocationsA resample query can be used to trigger out-of-memory crashes in Grafana. | CVSS6.5v3.1 | EPSS0.376% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-28375MEDIUM | Grafana Testdata datasource can issue unbounded memory allocationsA testdata data-source can be used to trigger out-of-memory crashes in Grafana. CWE-400Mar 27, 2026 | CVSS6.5v3.1 | EPSS0.376% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-27876CRITICAL | RCE on Grafana via sqlExpressionsA chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid future attack vectors going this path. Only instances with the sqlExpressions feature toggle enabled are vulnerable. Only instances in the following version ranges are affected: - 11.6.0 (inclusive) to 11.6.14 (exclusive): 11.6.14 has the fix. 11.5 and below are not… | CVSS9.1v3.1 | EPSS1.93% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-27880HIGH | OpenFeature evaluation API reads input data with no boundsThe OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes. | CVSS7.5v3.1 | EPSS0.772% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-27877MEDIUM | Public dashboards discloses all direct mode datasourcesWhen using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as possible to improve your deployments' security. | CVSS6.5v3.1 | EPSS0.309% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Authorization Bypass via TOCTOU in Grafana Datasource Deletion by NameA time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so. This requires several very stringent conditions to be met: - The attacker must have admin access to the specific datasource prior to its first deletion. - Upon deletion, all steps within the attack must happen within the next 30 seconds and on the same pod of Grafana. - The attacker must delete the datasource, then someone must recreate it. - The n… CWE-367Feb 25, 2026 | CVSS2.6v3.1 | EPSS0.161% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2025-6197MEDIUM | Open Redirect via Organization SwitchingAn open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites for exploitation: - Multiple organizations must exist in the Grafana instance - Victim must be on a different organization than the one specified in the URL | CVSS4.2v3.1 | EPSS66.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2025-6023HIGH | Grafana is vulnerable to XSS attacks through open redirects and path traversalAn open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vulnerability was introduced in Grafana v11.5.0. The open redirect can be chained with path traversal vulnerabilities to achieve XSS. Fixed in versions 12.0.2+security-01, 11.6.3+security-01, 11.5.6+security-01, 11.4.6+security-01 and 11.3.8+security-01 | CVSS7.6v3.1 | EPSS39.1% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-3415MEDIUM | Grafana's insecure DingDing Alert integration exposes sensitive informationGrafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not properly protected and could be exposed to users with Viewer permission. Fixed in versions 10.4.19+security-01, 11.2.10+security-01, 11.3.7+security-01, 11.4.5+security-01, 11.5.5+security-01, 11.6.2+security-01 and 12.0.1+security-01 | CVSS4.3v3.1 | EPSS0.956% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
Very long unicode dashboard title or panel name can hang the frontendIn Grafana, an excessively long dashboard title or panel name will cause Chromium browsers to become unresponsive due to Improper Input Validation vulnerability in Grafana. This issue affects Grafana: before 11.6.2 and is fixed in 11.6.2 and higher. CWE-20Jun 18, 2025 | CVSS2.7v3.1 | EPSS0.394% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2025-3454MEDIUM | Grafana's datasource proxy API allows authorization checks to be bypassedThis vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources. The issue primarily affects datasources that implement route-specific permissions, including Alertmanager and certain Prometheus-based datasources. CWE-285Jun 2, 2025 | CVSS5.0v3.1 | EPSS0.414% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-3260HIGH | Grafana vulnerable to authenticated users bypassing dashboard, folder permissionsA security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows authenticated users to bypass dashboard and folder permissions. The vulnerability affects all API versions (v0alpha1, v1alpha1, v2alpha1). Impact: - Viewers can view all dashboards/folders regardless of permissions - Editors can view/edit/delete all dashboards/folders regardless of permissions - Editors can create dashboards in any folder regardless of permissions - Anonymous users with viewer/editor roles are si… CWE-863Jun 2, 2025 | CVSS8.3v3.1 | EPSS0.505% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-3580MEDIUM | An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint. The vulnerability can be exploited when: 1. An Organization administrator exists 2. The Server administrator is either: - Not part of any organization, or - Part of the same organization as the Organization administrator Impact: - Organization administrators can per… CWE-284May 23, 2025 | CVSS5.5v3.1 | EPSS0.428% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-4123HIGH | Grafana Cross-Site-Scripting (XSS) via custom loaded frontend pluginA cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path traversal and open redirect. This allows attackers to redirect users to a website that hosts a frontend plugin that will execute arbitrary JavaScript. This vulnerability does not require editor permissions and if anonymous access is enabled, the XSS will work. If the Grafana Image Renderer plugin is installed, it is possible to exploit the open redirect to achieve a full read SSRF. The default Content… | CVSS7.6v3.1 | EPSS98.4% | PoCs6 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2025-2703MEDIUM | The built-in XY Chart plugin is vulnerable to a DOM XSS vulnerability. A user with Editor permissions is able to modify such a panel in order to make it execute arbitrary JavaScript. CWE-79Apr 23, 2025 | CVSS6.8v3.1 | EPSS18.2% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-11741MEDIUM | Grafana Alerting VictorOps integration could be exposed to users with Viewer permissionGrafana is an open-source platform for monitoring and observability. The Grafana Alerting VictorOps integration was not properly protected and could be exposed to users with Viewer permission. Fixed in versions 11.5.0, 11.4.1, 11.3.3, 11.2.6, 11.1.11, 11.0.11 and 10.4.15 CWE-200Jan 31, 2025 | CVSS4.3v3.1 | EPSS0.374% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Grafana org admin can delete pending invites in different orgOrganization admins can delete pending invites created in an organization they are not part of. CWE-639Oct 29, 2024 | CVSS-v4.0 | EPSS0.486% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2024-9264CRITICAL | Grafana SQL Expressions allow for remote code executionThe SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input. These queries are insufficiently sanitized before being passed to `duckdb`, leading to a command injection and local file inclusion vulnerability. Any user with the VIEWER or higher permission is capable of executing this attack. The `duckdb` binary must be present in Grafana's $PATH for this attack to function; by default, this binary is not installed in Grafana distribution… | CVSS9.4v4.0 | EPSS94.6% | PoCs14 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-8118MEDIUM | Grafana alerting wrong permission on datasource rule write endpointIn Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules. CWE-653Sep 26, 2024 | CVSS5.1v4.0 | EPSS0.583% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Grafana plugin data sources vulnerable to access control bypassAccess control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is granted associated access to any other data source, as the ReqActions check was not scoped to each specific datasource. The account must have prior query access to the impacted datasource. CWE-266Aug 20, 2024 | CVSS-v4.0 | EPSS0.305% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Users outside an organization can delete a snapshot with its keyIt is possible for a user in a different organization from the owner of a snapshot to bypass authorization and delete a snapshot by issuing a DELETE request to /api/snapshots/<key> using its view key. This functionality is intended to only be available to individuals with the permission to write/edit to the snapshot in question, but due to a bug in the authorization logic, deletion requests issued by an unprivileged user in a different organization than the snapshot owner are treated as authoriz… CWE-639Mar 26, 2024 | CVSS-v4.0 | EPSS0.646% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
User with permissions to create a data source can CRUD all data sourcesA user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user access to read, query, edit and delete all data sources within the organization. CWE-269Mar 7, 2024 | CVSS-v4.0 | EPSS0.802% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2023-6152MEDIUM | Email Validation Bypass And Preventing Sign Up From Email's OwnerA user changing their email after signing up and verifying it can change it without verification in profile settings. The configuration option "verify_email_enabled" will only validate email only on sign up. CWE-863Feb 13, 2024 | CVSS5.4v3.1 | EPSS1.39% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-3010HIGH | Grafana is an open-source platform for monitoring and observability. The WorldMap panel plugin, versions before 1.0.4 contains a DOM XSS vulnerability. CWE-79Oct 25, 2023 | CVSS7.3v3.1 | EPSS0.45% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-3128CRITICAL | Grafana vulnerable to Authentication Bypass by SpoofingGrafana is validating Azure AD accounts based on the email claim. On Azure AD, the profile email field is not unique and can be easily modified. This leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app. CWE-290Jun 22, 2023 | CVSS9.4v3.1 | EPSS4% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |