Data Exposure in Grafana Alert Rules API by Grafana
CVE-2026-13719
4.3MEDIUM
Key Information:
- Vendor
Grafana
- Vendor
- CVE Published:
- 30 September 2026
What is CVE-2026-13719?
A vulnerability in Grafana allows authenticated users to access alert rules stored in unauthorized folders via the alert rules API. Under certain circumstances, when the user's folder access is empty, the restriction is bypassed, causing all alert rules in the organization to be revealed. This can be triggered by any user in Grafana version 13.1.0 or later by using a folder filter. While the rules' configurations are exposed, sensitive data source credentials remain secure.
Affected Version(s)
Grafana Enterprise 12.3.0 <= 12.3.11
Grafana Enterprise 12.4.0 < 12.4.12
Grafana Enterprise 13.0.0 < 13.0.10