Executive brief
Grafana's Tempo and Loki data source plugins contain a security flaw that allows users with basic 'Viewer' permissions to manipulate web requests. This could allow an attacker to steal sensitive administrative credentials, shut down internal monitoring services, or access private data from internal systems. This vulnerability poses a risk to the confidentiality of system credentials and the availability of monitoring infrastructure.
Technical details
A path traversal vulnerability exists in the Tempo and Loki datasource plugins due to improper sanitization of user-supplied input during the construction of backend HTTP request URL paths. An authenticated attacker with 'Viewer' privileges can exploit this by crafting malicious inputs to traverse the URL path. This enables three primary attack vectors: capturing 'secureJsonData' custom headers (credentials) by redirecting requests to an attacker-controlled endpoint, invoking administrative actions on Tempo such as '/flush' or '/shutdown', and exfiltrating internal service data via Loki's 'CallResource' which returns full HTTP response bodies. The vulnerability is confirmed in Grafana OSS version 11.6.0.
Affected products
- Grafana Grafana OSS 11.6.0
Timeline
- 2026-06-22: disclosed
- 2026-06-22: advisory