CVE-2026-10601

A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative actions on the configured backend.
Configurations

Configuration 1 (hide)

cpe:2.3:a:grafana:grafana:11.6.0:-:*:*:-:*:*:*

History

No history.

Information

Published : 2026-06-22 14:16

Updated : 2026-07-10 16:16


NVD link : CVE-2026-10601

Mitre link : CVE-2026-10601

CVE.ORG link : CVE-2026-10601


JSON object : View

Products Affected

grafana

  • grafana
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')