| CVE-2026-19475 | medium | 6.5 | An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-333… | Sep 2, 2026 | Sep 3, 2026 |
| CVE-2026-14199 | high | 7.1 | Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (syn… | Sep 2, 2026 | Sep 3, 2026 |
| CVE-2026-12704 | medium | 6.8 | When SAML IdP-initiated login is enabled in Grafana Enterprise, the SAML library skips validation of… | Sep 2, 2026 | Sep 3, 2026 |
| CVE-2026-19854 | medium | 6.1 | When the ClickHouse plugin uses Native protocol (the default) with PDC or secure SOCKS, it asks for … | Aug 27, 2026 | Aug 31, 2026 |
| CVE-2026-19197 | medium | 6.3 | A user with organization administrator permissions can delete dashboard snapshots belonging to other… | Aug 26, 2026 | Aug 31, 2026 |
| CVE-2026-17033 | medium | 6.8 | An authenticated attacker with Editor access or alert.instances.external:write can submit an externa… | Aug 24, 2026 | Aug 31, 2026 |
| CVE-2026-17183 | high | 7.1 | An authenticated user with permission to create or edit alert rules can bypass datasource query auth… | Aug 19, 2026 | Aug 31, 2026 |
| CVE-2026-19516 | critical | 9.1 | A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound re… | Aug 11, 2026 | Aug 12, 2026 |
| CVE-2026-72585 | medium | 6.5 | An authorization bypass vulnerability in Grafana through 13.2.0 allows an Editor-role user to delete… | Aug 10, 2026 | Aug 18, 2026 |
| CVE-2026-9765 | high | 7.1 | Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue.
… | Jul 24, 2026 | Jul 24, 2026 |
| CVE-2026-21723 | medium | 5.3 | The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) ca… | Jul 23, 2026 | Aug 12, 2026 |
| CVE-2026-21729 | high | 7.5 | Loki queries with large limits can cause large memory allocations which can impact the availability … | Jul 16, 2026 | Aug 12, 2026 |
| CVE-2026-15583 | high | 8.6 | A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate… | Jul 15, 2026 | Aug 12, 2026 |
| CVE-2026-8595 | medium | 6.8 | A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a maliciou… | Jul 10, 2026 | Aug 12, 2026 |
| CVE-2026-8609 | medium | 5.3 | An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, caus… | Jul 10, 2026 | Aug 12, 2026 |
| CVE-2026-33382 | high | 7.5 | Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request bo… | Jul 10, 2026 | Aug 12, 2026 |
| CVE-2026-28378 | low | 3.1 | The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admi… | Jul 7, 2026 | Aug 12, 2026 |
| CVE-2026-42127 | high | 7.5 | The public dashboard query endpoint does not limit request body size before processing, allowing una… | Jun 22, 2026 | Aug 12, 2026 |
| CVE-2026-28381 | critical | 9.6 | The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run qu… | Jun 22, 2026 | Jun 30, 2026 |
| CVE-2026-9029 | high | 7.3 | A user with Editor permissions can place a malicious script in the attribution field of a Geomap pan… | Jun 22, 2026 | Aug 12, 2026 |
| CVE-2026-10601 | medium | 5.4 | A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source … | Jun 22, 2026 | Aug 12, 2026 |
| CVE-2026-42129 | high | 7.7 | A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach admi… | Jun 22, 2026 | Aug 12, 2026 |
| CVE-2026-27878 | medium | 6.5 | A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to a… | Jun 19, 2026 | Aug 12, 2026 |
| CVE-2026-11769 | medium | 6.4 | We have released version 5.24.0 of the Grafana Operator. This patch includes a MEDIUM severity secur… | Jun 13, 2026 | Aug 12, 2026 |
| CVE-2026-28374 | medium | 4.3 | Editors could delete any annotation, even those they do not have read access to. The editor user can… | May 13, 2026 | Aug 12, 2026 |