CVE-2026-17183

Summary

An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a server-side expression while referencing a real datasource UID (incorrect authorization). This can expose data accessible through Grafana's configured datasource credentials to users who lack permission to query that datasource.

Affected Software

VendorProductVersion RangeStatus
GrafanaGrafana OSS8.4.0 < 12.3.11affected
GrafanaGrafana OSS12.4.0 < 12.4.9affected
GrafanaGrafana OSS13.0.0 < 13.0.7affected
GrafanaGrafana OSS13.1.0 < 13.1.4affected
GrafanaGrafana Enterprise8.4.0 < 12.3.11affected
GrafanaGrafana Enterprise12.4.0 < 12.4.9affected
GrafanaGrafana Enterprise13.0.0 < 13.0.7affected
GrafanaGrafana Enterprise13.1.0 < 13.1.4affected

Weaknesses

  • CWE-863: CWE-863: INCORRECT AUTHORIZATION

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References