Data Exposure in Grafana Alert Rules API by Grafana
CVE-2026-13719

4.3MEDIUM

Key Information:

Vendor

Grafana

Vendor
CVE Published:
30 September 2026

What is CVE-2026-13719?

A vulnerability in Grafana allows authenticated users to access alert rules stored in unauthorized folders via the alert rules API. Under certain circumstances, when the user's folder access is empty, the restriction is bypassed, causing all alert rules in the organization to be revealed. This can be triggered by any user in Grafana version 13.1.0 or later by using a folder filter. While the rules' configurations are exposed, sensitive data source credentials remain secure.

Affected Version(s)

Grafana Enterprise 12.3.0 <= 12.3.11

Grafana Enterprise 12.4.0 < 12.4.12

Grafana Enterprise 13.0.0 < 13.0.10

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

mon3m (Researcher)
.