28,679 Entries 2,229 Sources 5 Verticals Last sync 9 minutes Live
OS & platform

Grafana

Grafana Labs
v11.6.14+security-04 bewährt latest release
12.05.2026

Upgrade assessment

Sicherheitsrelevant

Zeitnah aktualisieren

43 CVE(s) zuletzt, höchste Schwere: kritisch

Derived automatically from release, repo and CVE data — no judgment by a language model.

Specsattributes
gh_etagW/"cb5c24d4e15e4874036624cb20908530e3147e6be66eb0be070dca2fda7bb3be"
gh_checked_at2026-06-08T02:15:00.127061+00:00
Timelinealle Einträge
Type Ereignis · Quelle Value · Time
CVE
OS & platform Medium

A vulnerability in Grafana allows authenticated users to read arbitrary files from the server when the SQL Expressions feature is enabled.

CVE-2026-33380
06.06.2026
CVE
OS & platform Medium

A vulnerability in Grafana allows authenticated users to consume unlimited memory through special requests to plugin endpoints, potentially crashing the server and causing service disruption.

affects: ≥8.5.0 <11.6.14; ≥12.2.0 <12.2.8; ≥12.3.0 <12.3.6; ≥12.4.0 <12.4.3; =11.6.14; =12.2.8; =12.3.6; =12.4.3 · v11.6.14+security-04 not affected

CVE-2026-28383
06.06.2026
CVE
OS & platform Medium

A vulnerability in Grafana Live allows authenticated users with Viewer permissions to crash the server through concurrent requests, causing complete service outage until restart.

affects: ≥8.5.0 <11.6.14; ≥12.2.0 <12.2.8; ≥12.3.0 <12.3.6; ≥12.4.0 <12.4.3; =11.6.14; =12.2.8; =12.3.6; =12.4.3 · v11.6.14+security-04 not affected

CVE-2026-28379
06.06.2026
CVE
OS & platform Medium

A vulnerability in Grafana's Live push feature allows authenticated users to cause unlimited memory consumption by sending large amounts of data, potentially leading to system crashes.

affects: ≥8.0.0 <11.6.14; ≥12.0.0 <12.2.8; ≥12.3.0 <12.3.6; ≥12.4.0 <12.4.3; =11.6.14; =12.2.8; =12.3.6; =12.4.3 · v11.6.14+security-04 not affected

CVE-2026-28376
06.06.2026
CVE
OS & platform Low

A vulnerability in Grafana's Correlations feature allows users with datasource management privileges to view and permanently delete legacy correlation data belonging to other organizations, bypassing tenant isolation.

affects: <11.6.11; ≥12.0.0 <12.0.9; ≥12.1.0 <12.1.6; ≥12.2.0 <12.2.4; ≥12.3.0 <12.3.3 · v11.6.14+security-04 not affected

CVE-2026-21727
06.06.2026
CVE
OS & platform Medium

In Grafana's notification system, users with edit permissions can modify endpoint URLs of other users' contact points and capture confidential credentials like Slack tokens through the test function, enabling unauthorized access to external services.

affects: ≥8.0.0 ≤12.3.0 · your v11.6.14+security-04 affected

CVE-2025-12141
06.06.2026
CVE
OS & platform Medium

A vulnerability in Grafana's test data source can be exploited to cause memory issues that crash the application.

affects: <8.1.0; ≥11.6.14 <12.0.0; ≥12.1.10 <12.2.0; ≥12.2.8 <12.3.0; ≥12.3.6 <12.4.0 · your v11.6.14+security-04 affected

CVE-2026-28375
06.06.2026
CVE
OS & platform Medium

A vulnerability in Grafana allows attackers to cause system crashes by overwhelming memory through specially crafted resample queries, leading to denial of service.

affects: <8.0.0; ≥11.6.14 <12.0.0; ≥12.1.10 <12.2.0; ≥12.2.8 <12.3.0; ≥12.3.6 <12.4.0 · your v11.6.14+security-04 affected

CVE-2026-27879
06.06.2026
CVE
OS & platform Critical

A vulnerability in Grafana allows attackers to execute arbitrary code on the server through a combination of SQL expressions and Enterprise plugins. Only instances with the sqlExpressions feature enabled in specific versions between 11.6.0 and 12.4.1 are affected.

affects: <11.6.0; ≥11.6.14 <12.0.0; ≥12.1.10 <12.2.0; ≥12.2.8 <12.3.0; ≥12.3.6 <12.4.0 · your v11.6.14+security-04 affected

CVE-2026-27876
06.06.2026
CVE
OS & platform High

A vulnerability in Grafana Tempo exposes the S3 encryption key in plain text through a status endpoint, allowing unauthorized individuals to access the key used for encrypted trace data.

CVE-2026-28377
06.06.2026
CVE
OS & platform Medium

A vulnerability in Grafana's MSSQL plugin allows low-privileged users to bypass security restrictions and crash the server by causing excessive memory consumption.

affects: ≥11.6.0 <11.6.14; ≥12.1.0 <12.1.10; ≥12.2.0 <12.2.8; ≥12.3.0 <12.3.6; ≥12.4.0 <12.4.2 · v11.6.14+security-04 not affected

CVE-2026-33375
06.06.2026
CVE
OS & platform Medium

A vulnerability in Grafana allows users with Editor role to modify protected webhook URLs despite lacking the required permissions for such changes.

affects: ≥11.6.9 <11.6.14; ≥12.1.5 <12.1.10; ≥12.2.2 <12.2.8; ≥12.3.1 <12.3.6 · v11.6.14+security-04 not affected

CVE-2026-21724
06.06.2026
CVE
OS & platform High

A security vulnerability in the Grafana Cubism panel plugin allows attackers with editor privileges to inject malicious JavaScript code that executes when other users interact with the panel.

affects: ≤0.1.2 · v11.6.14+security-04 not affected

CVE-2026-32117
06.06.2026
CVE
OS & platform Low

A vulnerability in Grafana allows attackers to delete data sources without permission if they were previously deleted and then recreated. This requires very specific conditions to be met and only works within a 30-second window.

affects: ≥11.0.0 <12.4.1 · your v11.6.14+security-04 affected

CVE-2026-21725
06.06.2026
CVE
OS & platform Medium

A vulnerability in Grafana's Explore Traces view allows attackers to inject malicious JavaScript code through stack traces, which then executes in the browser. Only data sources using Jaeger HTTP API are affected.

affects: ≥12.2.0 <12.2.4; ≥12.3.0 <12.3.2; =12.2.4; =12.3.2 · v11.6.14+security-04 not affected

CVE-2025-41117
06.06.2026
CVE
OS & platform Critical

A critical security vulnerability in Grafana allows attackers to access and delete dashboard snapshots without authentication by using specific URL paths.

CVE-2021-39226
06.06.2026
CVE
OS & platform Medium

A vulnerability in Grafana allows attackers to execute malicious JavaScript code through specially crafted URLs when users are unauthenticated and visit certain pages.

CVE-2021-41174
06.06.2026
CVE
OS & platform Critical

A vulnerability in Grafana allowed organization administrators to manage user roles in other organizations where they had no authority. This only affected installations with the fine-grained access control beta feature enabled and multiple organizations present.

CVE-2021-41244
06.06.2026
CVE
OS & platform High

Grafana versions 8.0.0-beta1 through 8.3.0 contain a path traversal vulnerability that allows attackers to access local server files through specific plugin URLs.

CVE-2021-43798
06.06.2026
CVE
OS & platform Medium

Grafana applications between versions 5.0.0 and 8.3.1 contain a security vulnerability that allows authenticated users to read certain markdown files through directory traversal attacks.

CVE-2021-43813
06.06.2026
CVE
OS & platform Medium

Grafana contains a security vulnerability that allows authenticated users to read arbitrary CSV files through directory traversal, but only when the TestData DB data source is enabled.

CVE-2021-43815
06.06.2026
CVE
OS & platform Medium

A flaw in Grafana allows API token holders to access data they shouldn't have permission for by forwarding the OAuth identity of the most recently logged-in user.

CVE-2022-21673
06.06.2026
CVE
OS & platform Medium

Grafana versions up to 8.3.4 contain a Cross-Site Scripting vulnerability where attackers can inject malicious HTML code through compromised data sources or plugins. Authenticated users could be tricked into executing malicious code through specially crafted links.

CVE-2022-21702
06.06.2026
CVE
OS & platform Medium

Grafana dashboards are vulnerable to Cross-Site Request Forgery attacks where attackers can trick authenticated users into granting them high privileges. All versions from 3.0-beta1 onwards are affected, allowing privilege escalation by deceiving administrators.

CVE-2022-21703
06.06.2026
CVE
OS & platform Medium

Grafana versions from 5.0.0-beta1 onwards have a vulnerability in the Teams API that allows authenticated attackers to access team data they should not have permission to view.

CVE-2022-21713
06.06.2026
CVE
OS & platform High

A vulnerability in Grafana Enterprise allows attackers to gain elevated privileges when the fine-grained access control beta feature is enabled and multiple API keys with different roles are used.

CVE-2022-24812
06.06.2026
CVE
OS & platform Medium

Grafana Enterprise has a vulnerability that allows attackers to bypass network restrictions for data sources by using HTTP redirects to access servers that should be blocked.

CVE-2022-29170
06.06.2026
CVE
OS & platform High

Grafana versions 8.0 and later contain a stored Cross-Site Scripting vulnerability in the Unified Alerting feature. Attackers can exploit this to escalate their privileges from Editor to Admin by tricking authenticated administrators into clicking a malicious link.

CVE-2022-31097
06.06.2026
CVE
OS & platform High

A vulnerability in Grafana's OAuth authentication allows malicious users to take over existing user accounts. All Grafana versions from 5.3 onwards are affected and should be updated immediately.

CVE-2022-31107
06.06.2026
CVE
OS & platform Medium

A vulnerability in Grafana allows attackers to bypass plugin signature verification and install malicious plugins even when unsigned plugins should be blocked by security settings.

CVE-2022-31123
06.06.2026
CVE
OS & platform Medium

A vulnerability in Grafana allows certain plugins to intercept user authentication tokens, potentially exposing sensitive login credentials.

CVE-2022-31130
06.06.2026
CVE
OS & platform Medium

A vulnerability in Grafana allows administrators to escalate their privileges to Server Admin when Auth Proxy authentication is used. Attackers can create a fake datasource pointing to localhost that contains admin user credentials to gain elevated access.

CVE-2022-35957
06.06.2026
CVE
OS & platform Medium

A flaw in Grafana's role-based access control allows users with Editor or Viewer permissions to access folders and dashboards that should only be available to Administrators.

CVE-2022-36062
06.06.2026
CVE
OS & platform Medium

A security vulnerability in Grafana allows plugins to receive user authentication cookies, which occurs under certain conditions at data source and plugin proxy endpoints.

CVE-2022-39201
06.06.2026
CVE
OS & platform Medium

Grafana has an authentication flaw where an attacker can prevent legitimate users from logging in by registering a username that matches another user's email address.

CVE-2022-39229
06.06.2026
CVE
OS & platform Medium

Grafana has a vulnerability in invitation links that allows attackers to register with arbitrary usernames or email addresses to gain unauthorized access to organizations.

CVE-2022-39306
06.06.2026
CVE
OS & platform Medium

Grafana applications up to version 9.x have a vulnerability that allows attackers to discover which usernames or email addresses exist in the system by abusing the password reset function.

CVE-2022-39307
06.06.2026
CVE
OS & platform Medium

In Grafana, users with Viewer permissions can inject arbitrary URLs when creating dashboard snapshots, which are then displayed to other users as trusted links to the original dashboard.

CVE-2022-39324
06.06.2026
CVE
OS & platform Critical

A race condition in Grafana allows unauthenticated users to query protected endpoints because under heavy load HTTP requests can receive incorrect authentication middleware from other calls.

CVE-2022-39328
06.06.2026
CVE
OS & platform High

A vulnerability in Grafana Enterprise allows attackers to escalate their privileges by manipulating SAML responses containing multiple assertions. Only unsigned SAML documents with at least one signed assertion are affected, potentially allowing attackers to gain administrative access.

CVE-2022-41912
06.06.2026
CVE
OS & platform High

A flaw in Grafana Enterprise allows users to receive other users' session cookies when datasource query caching is enabled, potentially granting unauthorized access to other user accounts.

CVE-2022-23498
06.06.2026
CVE
OS & platform High

A vulnerability in Grafana's GeoMap plugin allows users with Editor permissions to inject malicious JavaScript code through SVG files, which then executes in other users' browsers and can be exploited for privilege escalation.

CVE-2022-23552
06.06.2026
CVE
OS & platform Medium

A security vulnerability in Grafana's Text plugin allows users with Editor permissions to store malicious JavaScript code that executes when Admin users edit the panel and click specific options.

CVE-2023-22462
06.06.2026
REL
OS & platform Critical bewährt

Security update fixes ten CVE vulnerabilities in Grafana

v11.6.14+security-04
12.05.2026
REL
OS & platform Critical bewährt

Security update fixes ten CVE vulnerabilities in Grafana

v12.2.8+security-04
12.05.2026
REL
OS & platform Critical bewährt

Security update fixes critical vulnerabilities and an error when updating Alertmanager configuration

v12.3.6+security-04
12.05.2026
REL
OS & platform Critical bewährt

Security update with fixes for ten CVE vulnerabilities

v12.4.3+security-02
12.05.2026
REL
OS & platform Critical bewährt

Security update fixes ten CVE vulnerabilities in Grafana

v13.0.1+security-01
12.05.2026
REL
OS & platform Low bewährt

Grafana 13.0.1 fixes unified storage migration issues and improves dashboard timezone handling and provisioning validation

v13.0.1
17.04.2026
REL
OS & platform Low bewährt

Maintenance update with Go upgrade to version 1.25.9, improvements to analytics and reporting features, and documentation fix for alerting metrics

v12.4.3
14.04.2026
REL
OS & platform Critical bewährt

Security update with fixes for four CVE vulnerabilities

v11.6.14
26.03.2026
REL
OS & platform Critical bewährt

Security update with fixes for multiple CVE vulnerabilities

v12.1.10
26.03.2026
REL
OS & platform Critical bewährt

Security update fixes multiple CVE vulnerabilities

v12.2.8
26.03.2026
REL
OS & platform Critical bewährt

Security update with fixes for multiple CVE vulnerabilities and improved Public Dashboard security across organizations

v12.3.6
26.03.2026
REL
OS & platform High bewährt

Security update fixes critical vulnerability CVE-2026-33375

v11.6.14+security-01
25.03.2026
REL
OS & platform High bewährt

Security update fixes critical vulnerability CVE-2026-33375

v12.1.10+security-01
25.03.2026
REL
OS & platform High bewährt

Security update fixes critical vulnerability CVE-2026-33375

v12.2.8+security-01
25.03.2026
REL
OS & platform High bewährt

Security update fixes critical vulnerability CVE-2026-33375

v12.3.6+security-01
25.03.2026
REL
OS & platform High bewährt

Patch release with security fixes for multiple CVEs, accessibility improvements, and bug fixes for plugins and dashboards

v12.4.2
25.03.2026
REL
OS & platform Low bewährt

Go runtime updated to version 1.25.8

v11.6.13
09.03.2026
REL
OS & platform Low bewährt

Updated Go runtime to version 1.25.8 and added support for custom CA certificates in Image Renderer

v12.1.9
09.03.2026
REL
OS & platform Low bewährt

Maintenance update with Go 1.25.8, custom CA certificate support in Image Renderer, and fix for dashboard versions list API

v12.2.7
09.03.2026
REL
OS & platform Low bewährt

Maintenance update with Go 1.25.8, custom CA certificate support in Image Renderer and fix for dashboard versions list API

v12.3.5
09.03.2026
REL
OS & platform Low bewährt

Maintenance update with Go upgrade to 1.25.8, improved access control and bug fixes for alerting and MariaDB compatibility

v12.4.1
09.03.2026
REL
OS & platform Low bewährt

Grafana 12.4.0 introduces extensive alerting improvements with new UI features, RBAC permissions, and performance optimizations

v12.4.0
25.02.2026
REL
OS & platform bewährt

Grafana v11.6.12 has been released with download links and documentation for new features

v11.6.12
24.02.2026
REL
OS & platform Low bewährt

Bug fix for datasource variable templating in dashboard export

v12.1.8
24.02.2026
REL
OS & platform Low bewährt

Bug fix for datasource variable templating in dashboard export

v12.2.6
24.02.2026
REL
OS & platform Low bewährt

Bug fixes for dashboard export with datasource variables and provisioning with nanogit library

v12.3.4
24.02.2026
REL
OS & platform Low bewährt

Grafana 12.0.10 adds size limits for expanded notification templates and improves security for public dashboard annotations

v12.0.10
12.02.2026
REL
OS & platform Medium Breaking

Grafana 12.1.7 removes support for org_id=0 in correlations, adds size limits for notification templates, and updates Go to version 1.25.7

v12.1.7
12.02.2026
REL
OS & platform Medium Breaking

Grafana 12.2.5 removes support for org_id=0 in correlations, adds limits for notification templates and fixes security issues

v12.2.5
12.02.2026
REL
OS & platform Medium Breaking

Grafana 12.3.3 removes support for org_id=0 in correlations, adds limits for notification templates and fixes security issues

v12.3.3
12.02.2026