CVE-2026-42129

A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.
Configurations

Configuration 1 (hide)

cpe:2.3:a:grafana:loki_datasource:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-22 14:17

Updated : 2026-07-10 16:16


NVD link : CVE-2026-42129

Mitre link : CVE-2026-42129

CVE.ORG link : CVE-2026-42129


JSON object : View

Products Affected

grafana

  • loki_datasource
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')