grafana.comVendor advisory
https://grafana.com/security/security-advisories/cve-2026-42129 CVE-2026-42129
HIGH
Path traversal in the Loki data source plugin
Record summary
CVE-2026-42129 has a selected CVSS score of 7.7 (high).
Description
A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 22, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Grafana OSSBrowse Grafana / Grafana OSSDefault status: unaffected | CVE List | 11.6.0 to ≤ 11.6.14 | affected |
| 12.2.0 to ≤ 12.2.8 | affected | ||
| 12.3.0 to ≤ 12.3.6 | affected | ||
| 12.4.0 to ≤ 12.4.3 | affected | ||
| 13.0.0 to ≤ 13.0.1 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-42129