Authorization Bypass in Grafana OSS Affecting Alert Rules Management
CVE-2026-17183
7.1HIGH
What is CVE-2026-17183?
An authorization bypass vulnerability in Grafana OSS allows authenticated low-privileged users to execute queries against restricted datasources. This occurs when an attacker, possessing the rights to create or modify alert rules, submits a query with a client-controlled type that bypasses necessary permissions. As a result, sensitive data tied to the datasource UID can be exposed, compromising data confidentiality. The issue stems from inconsistent checks between the authorization phase and the execution of queries, permitting exploitation without proper user permissions or interactions.
Affected Version(s)
Grafana Enterprise 8.4.0 < 12.3.11
Grafana Enterprise 12.4.0 < 12.4.9
Grafana Enterprise 13.0.0 < 13.0.7