Remote Code Execution in Grafana OSS and Grafana Enterprise Plugin Installation
CVE-2026-15815

8.8HIGH

Key Information:

Vendor

Grafana

Vendor
CVE Published:
17 September 2026

What is CVE-2026-15815?

Grafana OSS and Grafana Enterprise contain a vulnerability where symbolic links are not securely handled during the extraction of plugin archives. A malicious plugin archive can use relative symbolic link entries to escape the designated plugin installation directory, allowing the malicious actor to write arbitrary files outside that directory. This can lead to the execution of harmful binaries with the same privileges as the Grafana server process. Additionally, since plugin archives are extracted prior to signature verification, even plugins with valid signatures can pose a threat. Operators might unwittingly install compromised plugins, whether they appear legitimate or are sourced from unknown archives using tools such as grafana-cli or environment variables.

Affected Version(s)

Grafana Enterprise 11.6.0 <= 11.6.17

Grafana Enterprise 12.0.0

Grafana Enterprise 12.1.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.