Path Traversal Vulnerability in Tempo and Loki Datasource Plugins by Grafana
CVE-2026-10601
5.4MEDIUM
What is CVE-2026-10601?
The Tempo and Loki datasource plugins by Grafana exhibit a vulnerability that arises from the way these plugins construct backend HTTP requests. Specifically, they interpolate user-supplied input into URL paths without proper sanitization. This flaw enables a possible path traversal attack, allowing an unauthorized Viewer-role user to exploit the vulnerability by accessing admin-configured datasource credentials and invoking crucial admin endpoints. This can lead to unauthorized data exfiltration and potential disruption of service. Adequate measures need to be taken to secure these plugins against such threats.
Affected Version(s)
Grafana OSS Cloud 11.6.0