LIVE · cybersecurity feed
Live wire
vendor

Grafana

8 CVEs published in the last four months. Exploited flaws first.

Critical1
High7
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-283819.6criticalsnowflakeThe Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against 75d ago
CVE-2026-117698.8highgrafana operatorWe have released version 5.24.0 of the Grafana Operator.85d ago
CVE-2026-421297.7highloki datasourceA user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Lok75d ago
CVE-2026-333827.5highgrafanaSeveral Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before proc57d ago
CVE-2026-421277.5highgrafanaThe public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated a75d ago
CVE-2026-333767.4highgrafanaWhen using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses.115d ago
CVE-2026-90297.3highgrafanaA user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile l75d ago
CVE-2026-333777.1highgrafanaAn Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard.115d ago

Filter the full tracker by Grafana