Home / CVEs we hold for Grafana CVEs we hold for Grafana Records whose assigning authority named Grafana as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-9029 Stored XSS in the Geomap panel tile-layer attribution Grafana OSS CVE-2026-8609 Pre-authentication denial of service via the OAuth login route Grafana OSS CVE-2026-63087 Grafana OnCall 1.16.11 Unauthenticated Token Hijack via Plugin Install Endpoint grafana-cold-storage oncall CVE-2026-42129 Path traversal in the Loki data source plugin Grafana OSS CVE-2026-42127 Pre-authentication denial of service in the public dashboard query endpoint Grafana OSS CVE-2026-33382 Denial of service via unbounded request body size Grafana OSS CVE-2026-33381 Users can generate Service Account tokens after permissions removal Grafana OSS CVE-2026-33378 Grafana Data Source Plugin: DoS (OOM) via Negative Interval Injection in $__timeGroup Macro Grafana OSS CVE-2026-33377 Dashboard Import Overwrites ACL — Editor Privilege Escalation to Dashboard Admin Grafana OSS CVE-2026-33375 Grafana MSSQL Data Source Plugin: Restriction Bypass Leading to OOM DoS Grafana OSS CVE-2026-28383 Grafana plugin resources can lead to unbounded memory allocation Grafana OSS CVE-2026-28381 Local File Read/Write to Potential Privilege Escalation via Snowflake GET/PUT Grafana Snowflake Datasource CVE-2026-28380 BAC in Snapshot API allows deletion of unauthorized dashboard snapshots Grafana OSS CVE-2026-28379 Viewer-triggered race condition in Grafana Live leads to complete server crash Grafana OSS CVE-2026-28378 Cross-Organization Public Dashboard Deletion via Missing Org Isolation Grafana OSS CVE-2026-28377 S3 SSE-C Encryption Key Exposed in Plaintext via Config Endpoint (CVE-2025-41118 Pattern) Grafana Tempo CVE-2026-28376 Grafana Live push endpoint allows unbounded memory allocation leading to OOM Grafana OSS CVE-2026-28375 Grafana Testdata datasource can issue unbounded memory allocations Grafana CVE-2026-28374 IDOR in Annotations API allows unprivileged users to DELETE annotation Grafana OSS CVE-2026-27880 OpenFeature evaluation API reads input data with no bounds Grafana CVE-2026-27879 Query resampling can cause unbounded memory allocations Grafana CVE-2026-27878 Tempo TraceQL query with exemplar hint could result in unbounded memory usage Grafana Tempo CVE-2026-27877 Public dashboards discloses all direct mode datasources Grafana CVE-2026-21729 Loki detected_fields query limits results in unbounded memory allocation Grafana Loki CVE-2026-21728 Tempo query limit results in unbounded memory allocation Grafana Enterprise Traces (GET) CVE-2026-21727 Grafana Correlations: Cross-Tenant Data Disclosure and Permanent Deletion via Legacy org_id=0 Record Grafana Correlations CVE-2026-21725 Authorization Bypass via TOCTOU in Grafana Datasource Deletion by Name Grafana CVE-2026-21724 Missing Protected-field Authorization in Provisioning Contact Points API Grafana OSS CVE-2026-21722 Public Dashboards time range restriction on annotations can be bypassed grafana/grafana; grafana/grafana-enterprise CVE-2026-21721 Dashboard Permissions Scope Bypass Enables Cross‑Dashboard Privilege Escalation grafana/grafana; grafana/grafana-enterprise CVE-2026-21720 Unauthenticated DoS: avatar cache leaks goroutines when /avatar/:hash requests time out grafana/grafana-enterprise; grafana/grafana CVE-2026-19475 SQL Data Source Plugin: OOM DoS via $__timeGroup macro Grafana Microsoft SQL Server Datasource CVE-2026-19197 Broken access control in dashboard snapshots Grafana Enterprise CVE-2026-15583 SSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL header Grafana MCP Server CVE-2026-14199 Session takeover via Auth Proxy cache key collision Grafana OSS CVE-2026-12704 SAML assertion replay via skipped InResponseTo validation Grafana Enterprise CVE-2026-11769 Operator - Namespaced User Path Traversal Grafana Operator CVE-2026-10601 Path traversal in the Tempo and Loki data source plugins Grafana OSS CVE-2025-8341 SSRF in Infinity Datasource Plugin grafana-infinity-datasource CVE-2025-41118 Sensitive COS `SecretKey` exposed in plaintext via configuration API due to missing type protection Grafana Pyroscope CVE-2025-41117 XSS in Grafana Explore stack trace grafana/grafana; grafana/grafana-enterprise CVE-2025-41116 Incorrect oauth passthrough in Grafana Databricks Datasource Grafana Databricks Datasource Plugin CVE-2025-3717 Incorrect oauth passthrough in Grafana Snowflake Datasource Grafana Snowflake Datasource Plugin CVE-2025-12141 Grafana Alerting Editors can edit destination of webhooks they did not create Grafana Alerting CVE-2025-11539 Arbitrary Code Execution in Grafana Image Renderer Plugin grafana-image-renderer CVE-2025-1088 Very long unicode dashboard title or panel name can hang the frontend Grafana CVE-2024-9476 Privilege escalation vulnerability for Organizations in Grafana Grafana OSS and Enterprise CVE-2024-9264 Grafana SQL Expressions allow for remote code execution Grafana CVE-2024-8996 Grafana Agent Flow on Windows Unquoted service path Grafana Agent Flow CVE-2024-8986 Information Leakage in grafana-plugin-sdk-go grafana-plugin-sdk-go Grafana Plugin SDK CVE-2024-8975 Grafana Alloy on Windows Unquoted service path Grafana Alloy CVE-2024-8118 Grafana alerting wrong permission on datasource rule write endpoint Grafana CVE-2024-1442 User with permissions to create a data source can CRUD all data sources Grafana CVE-2024-1313 Users outside an organization can delete a snapshot with its key Grafana CVE-2023-5123 Improper Path Sanitization in JSON Datasource Plugin grafana-json-datasource CVE-2023-1410 Stored XSS in Graphite FunctionDescription tooltip Grafana; Grafana Enterprise CVE-2022-46156 Grafana's default installation of `synthetic-monitoring-agent` exposes sensitive information grafana synthetic-monitoring-agent CVE-2022-39328 Grafana vulnerable to race condition allowing privilege escalation grafana CVE-2022-39324 Grafana vulnerable to spoofing originalUrl of snapshots grafana CVE-2022-39307 Grafana subject to Exposure of Sensitive Information resulting in User enumeration via forget password grafana CVE-2022-39229 Grafana users with email as a username can block other users from signing in grafana CVE-2022-39201 Data source and plugin proxy endpoints could leak the authentication cookie to some destination plugins grafana CVE-2022-36062 Grafana folders admin only permission privilege escalation grafana CVE-2022-35957 Authentication Bypass in Grafana via auth proxy allowing escalation from admin to server admin grafana CVE-2022-31176 Grafana Image Renderer leaking files grafana-image-renderer CVE-2022-31130 Grafana data source and plugin proxy endpoints leaking authentication tokens to some destination plugins grafana CVE-2022-29170 Grafana Enterprise datasource network restrictions bypass via HTTP redirects grafana CVE-2022-23498 When query caching is enabled in Grafana users can query another users session grafana CVE-2021-41174 XSS vulnerability allowing arbitrary JavaScript execution grafana 127 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.