Skip to content
Grafana LabsCVE-2026-17183

Grafana: improper authorization

High7.1CVE-2026-17183 · Published Aug 19, 2026 · updated Aug 31, 2026

An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a server-side expression while referencing a real datasource UID (incorrect authorization). This can expose data accessible through Grafana's configured datasource credentials to users who lack permission to query that datasource.

Grafana Labs advisory

Affected versions

PackageAffectedFixed in
Grafana Enterprise
Product
>= 8.4.0, < 12.3.1112.3.11
>= 12.4.0, < 12.4.912.4.9
>= 13.0.0, < 13.0.713.0.7
>= 13.1.0, < 13.1.413.1.4
Grafana OSS
Product
>= 8.4.0, < 12.3.1112.3.11
>= 12.4.0, < 12.4.912.4.9
>= 13.0.0, < 13.0.713.0.7
>= 13.1.0, < 13.1.413.1.4
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-863

More Grafana Labs advisories

All Grafana Labs
Advisory
Grafana Labs Alloy: exposed files
High7.7Aug 27
Grafana Labs Clickhouse Datasource: cleartext transmission
Medium6.1Aug 27
Grafana: improper access control
Medium6.3Aug 26
Grafana OSS: cross-site scripting
Medium6.8Aug 24
Grafana: information disclosure
Medium5.3Aug 17
Grafana MCP Server: server-side request forgery
Critical9.1Aug 11

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.