CVE-2026-10601

Summary

A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative actions on the configured backend.

Affected Software

VendorProductVersion RangeStatus
GrafanaGrafana OSS11.6.0 <= 11.6.14affected
GrafanaGrafana OSS12.2.0 <= 12.2.8affected
GrafanaGrafana OSS12.3.0 <= 12.3.6affected
GrafanaGrafana OSS12.4.0 <= 12.4.3affected
GrafanaGrafana OSS13.0.0 <= 13.0.1affected

Weaknesses

  • CWE-22: CWE-22

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References