grafana.comVendor advisory
https://grafana.com/security/security-advisories/cve-2026-10601 CVE-2026-10601
MEDIUM
Path traversal in the Tempo and Loki data source plugins
Record summary
CVE-2026-10601 has a selected CVSS score of 5.4 (medium).
Description
A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative actions on the configured backend.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 22, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Grafana OSSBrowse Grafana / Grafana OSSDefault status: unaffected | CVE List | 11.6.0 to ≤ 11.6.14 | affected |
| 12.2.0 to ≤ 12.2.8 | affected | ||
| 12.3.0 to ≤ 12.3.6 | affected | ||
| 12.4.0 to ≤ 12.4.3 | affected | ||
| 13.0.0 to ≤ 13.0.1 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-10601