A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative actions on the configured backend.
References
| Link | Resource |
|---|---|
| https://grafana.com/security/security-advisories/cve-2026-10601 | Broken Link |
Configurations
History
No history.
Information
Published : 2026-06-22 14:16
Updated : 2026-07-10 16:16
NVD link : CVE-2026-10601
Mitre link : CVE-2026-10601
CVE.ORG link : CVE-2026-10601
JSON object : View
Products Affected
grafana
- grafana
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
