← Back

CVE-2026-10601

nvd nist
Published: Jun 22, 2026Modified: Jul 10, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative actions on the configured backend.

Affected (1)

Products: Grafana: Grafana
1 product
Grafana
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.6.0

References (1)

Timeline

No history available yet.