Executive brief
Grafana is an observability and visualization platform used to monitor infrastructure and application performance. An authenticated user with alert rule creation or edit permissions can bypass datasource access controls by crafting malicious alert queries, allowing them to access data from datasources they should not be able to query. This could expose sensitive monitoring data and credentials to unauthorized users within the organization.
Technical details
The vulnerability is an authorization bypass in Grafana's alerting subsystem. An authenticated user with permission to create or edit alert rules can mark an alert rule query as a server-side expression while referencing a real datasource UID, circumventing the normal authorization checks that would block direct datasource access. The attack vector is network-based and requires valid Grafana authentication credentials and alert rule edit permissions (low privilege threshold). An attacker can retrieve data accessible through the datasource's configured credentials, potentially exposing sensitive metrics, logs, or other monitoring data. Patches are available in Grafana versions 12.3.11, 12.4.9, 13.0.7, 13.1.4, and 13.2.0 or later.
Affected products
- Grafana Grafana Enterprise <8.4.0, >=12.3.11 <12.4.0, >=12.4.9 <13.0.0, >=13.0.7 <13.1.0, >=13.1.4 <13.2.0
Timeline
- 2026-08-24: disclosed
- 2026-08-24: patched: Patches released in versions 12.3.11, 12.4.9, 13.0.7, 13.1.4, and 13.2.0+