CVE-2026-22639
- EPSS 0.04%
- Veröffentlicht 15.01.2026 13:12:03
- Zuletzt bearbeitet 22.01.2026 17:16:36
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-22638
- EPSS 0.04%
- Veröffentlicht 15.01.2026 13:11:21
- Zuletzt bearbeitet 22.01.2026 17:16:36
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-41115
- EPSS 0.06%
- Veröffentlicht 21.11.2025 14:25:38
- Zuletzt bearbeitet 08.01.2026 16:39:45
SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage users and teams in Grafana by introducing automated user lifecycle management. In Grafana versions 12.x where SCIM provisioning is ...
CVE-2025-6197
- EPSS 1.02%
- Veröffentlicht 18.07.2025 07:48:22
- Zuletzt bearbeitet 15.04.2026 00:35:42
An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites for exploitation: - Multiple organizations must exist in the Grafana instance - Victim must be on a different organization than ...
CVE-2025-6023
- EPSS 6.21%
- Veröffentlicht 18.07.2025 07:48:15
- Zuletzt bearbeitet 15.04.2026 00:35:42
An open redirect vulnerability has been identified in Grafana OSS that can be exploited to achieve XSS attacks. The vulnerability was introduced in Grafana v11.5.0. The open redirect can be chained with path traversal vulnerabilities to achieve XSS....
CVE-2025-3415
- EPSS 0.44%
- Veröffentlicht 17.07.2025 10:13:14
- Zuletzt bearbeitet 15.04.2026 00:35:42
Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not properly protected and could be exposed to users with Viewer permission. Fixed in versions 10.4.19+security-01, 11.2.10+security-0...
CVE-2025-1088
- EPSS 0.35%
- Veröffentlicht 18.06.2025 09:54:30
- Zuletzt bearbeitet 15.04.2026 00:35:42
In Grafana, an excessively long dashboard title or panel name will cause Chromium browsers to become unresponsive due to Improper Input Validation vulnerability in Grafana. This issue affects Grafana: before 11.6.2 and is fixed in 11.6.2 and higher.
- EPSS 0.05%
- Veröffentlicht 02.06.2025 10:34:09
- Zuletzt bearbeitet 15.04.2026 00:35:42
This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager a...
CVE-2025-3260
- EPSS 0.09%
- Veröffentlicht 02.06.2025 10:15:21
- Zuletzt bearbeitet 15.04.2026 00:35:42
A security vulnerability in the /apis/dashboard.grafana.app/* endpoints allows authenticated users to bypass dashboard and folder permissions. The vulnerability affects all API versions (v0alpha1, v1alpha1, v2alpha1). Impact: - Viewers can view all...
CVE-2025-3580
- EPSS 0.1%
- Veröffentlicht 23.05.2025 13:44:45
- Zuletzt bearbeitet 15.04.2026 00:35:42
An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint. The vulnerability can be e...