Path Traversal and Privilege Escalation in Grafana Operator
CVE-2026-11769
6.4MEDIUM
What is CVE-2026-11769?
A vulnerability in the Grafana Operator allows unauthorized users to create Dashboard or LibraryPanel resources, potentially leading to the exposure of sensitive Kubernetes service account tokens. This issue arises from the evaluation of jsonnet expressions within the operator manager pod, paving the way for privilege escalation. Users are advised to upgrade to version 5.24.0 or later to mitigate this risk. Alternatively, deploying a ValidatingAdmissionPolicy can help prevent the creation or modification of jsonnet resources until the upgrade is applied.
Affected Version(s)
Grafana Operator 0 <= 5.23.0