Path Traversal Vulnerability in Tempo and Loki Datasource Plugins by Grafana
CVE-2026-10601

5.4MEDIUM

Key Information:

Vendor

Grafana

Vendor
CVE Published:
22 June 2026

What is CVE-2026-10601?

The Tempo and Loki datasource plugins by Grafana exhibit a vulnerability that arises from the way these plugins construct backend HTTP requests. Specifically, they interpolate user-supplied input into URL paths without proper sanitization. This flaw enables a possible path traversal attack, allowing an unauthorized Viewer-role user to exploit the vulnerability by accessing admin-configured datasource credentials and invoking crucial admin endpoints. This can lead to unauthorized data exfiltration and potential disruption of service. Adequate measures need to be taken to secure these plugins against such threats.

Affected Version(s)

Grafana OSS Cloud 11.6.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

homb (Researcher)
.