CVE-2026-42129

Summary

A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.

Affected Software

VendorProductVersion RangeStatus
GrafanaGrafana OSS11.6.0 <= 11.6.14affected
GrafanaGrafana OSS12.2.0 <= 12.2.8affected
GrafanaGrafana OSS12.3.0 <= 12.3.6affected
GrafanaGrafana OSS12.4.0 <= 12.4.3affected
GrafanaGrafana OSS13.0.0 <= 13.0.1affected

Weaknesses

  • CWE-22: CWE-22

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References