Skip to content
Grafana LabsCVE-2026-13719

Grafana: information disclosure

Medium4.3CVE-2026-13719 · Published Sep 30, 2026

An authenticated user can list alert rules stored in folders they are not allowed to read through the alert rules API list endpoint. When the set of folders the user may read was empty, the folder restriction was dropped and every alert rule in the organization was returned. From Grafana 13.1.0, any user can trigger this with a folder filter. The exposed data is rule configuration; data source credentials are not exposed.

Grafana Labs advisory

Affected versions

PackageAffectedFixed in
Grafana Enterprise
Product
>= 12.3.0, <= 12.3.11No fix yet
>= 12.4.0, < 12.4.1212.4.12
>= 13.0.0, < 13.0.1013.0.10
>= 13.1.0, < 13.1.713.1.7
Grafana OSS
Product
>= 12.3.0, <= 12.3.11No fix yet
>= 12.4.0, < 12.4.1212.4.12
>= 13.0.0, < 13.0.1013.0.10
>= 13.1.0, < 13.1.713.1.7
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-200, CWE-863

More Grafana Labs advisories

All Grafana Labs
Advisory
Grafana: improper authorization
Medium5.4Sep 30
Grafana: missing authorization
Medium5.3Sep 29
Grafana: improper authorization
Medium4.3Sep 29
Grafana: cross-site scripting
High7.3Sep 17
Grafana: remote code execution
High8.8Sep 17
Grafana OSS: denial of service
Medium6.5Sep 2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.