S3 Encryption Key Exposure in Grafana Tempo by Grafana
CVE-2026-28377
7.5HIGH
What is CVE-2026-28377?
A vulnerability in Grafana Tempo allows unauthorized access to the S3 SSE-C encryption key, which can be retrieved in plaintext via the /status/config endpoint. This exposure poses significant security risks as it enables malicious actors to potentially decrypt trace data stored in S3. Users of Grafana Tempo are urged to apply the recommended security measures to mitigate this risk.
Affected Version(s)
Tempo OnPrem 2.10.3