Authorization Bypass in Grafana OSS Affecting Alert Rules Management
CVE-2026-17183

7.1HIGH

Key Information:

Vendor

Grafana

Vendor
CVE Published:
19 August 2026

What is CVE-2026-17183?

An authorization bypass vulnerability in Grafana OSS allows authenticated low-privileged users to execute queries against restricted datasources. This occurs when an attacker, possessing the rights to create or modify alert rules, submits a query with a client-controlled type that bypasses necessary permissions. As a result, sensitive data tied to the datasource UID can be exposed, compromising data confidentiality. The issue stems from inconsistent checks between the authorization phase and the execution of queries, permitting exploitation without proper user permissions or interactions.

Affected Version(s)

Grafana Enterprise 8.4.0 < 12.3.11

Grafana Enterprise 12.4.0 < 12.4.9

Grafana Enterprise 13.0.0 < 13.0.7

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

czarflix
.