Remote Code Execution in Grafana OSS and Grafana Enterprise Plugin Installation
CVE-2026-15815
Key Information:
- Vendor
Grafana
- Vendor
- CVE Published:
- 17 September 2026
What is CVE-2026-15815?
Grafana OSS and Grafana Enterprise contain a vulnerability where symbolic links are not securely handled during the extraction of plugin archives. A malicious plugin archive can use relative symbolic link entries to escape the designated plugin installation directory, allowing the malicious actor to write arbitrary files outside that directory. This can lead to the execution of harmful binaries with the same privileges as the Grafana server process. Additionally, since plugin archives are extracted prior to signature verification, even plugins with valid signatures can pose a threat. Operators might unwittingly install compromised plugins, whether they appear legitimate or are sourced from unknown archives using tools such as grafana-cli or environment variables.
Affected Version(s)
Grafana Enterprise 11.6.0 <= 11.6.17
Grafana Enterprise 12.0.0
Grafana Enterprise 12.1.0