Path Traversal and Privilege Escalation in Grafana Operator
CVE-2026-11769

6.4MEDIUM

Key Information:

Vendor

Grafana

Vendor
CVE Published:
13 June 2026

What is CVE-2026-11769?

A vulnerability in the Grafana Operator allows unauthorized users to create Dashboard or LibraryPanel resources, potentially leading to the exposure of sensitive Kubernetes service account tokens. This issue arises from the evaluation of jsonnet expressions within the operator manager pod, paving the way for privilege escalation. Users are advised to upgrade to version 5.24.0 or later to mitigate this risk. Alternatively, deploying a ValidatingAdmissionPolicy can help prevent the creation or modification of jsonnet resources until the upgrade is applied.

Affected Version(s)

Grafana Operator 0 <= 5.23.0

References

CVSS V4

Score:
6.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

cherez0ff
.