Record summary

CVE-2026-10601 has a selected CVSS score of 5.4 (medium).

Description

A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative actions on the configured backend.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 22, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List11.6.0 to ≤ 11.6.14affected
12.2.0 to ≤ 12.2.8affected
12.3.0 to ≤ 12.3.6affected
12.4.0 to ≤ 12.4.3affected
13.0.0 to ≤ 13.0.1affected

References

2