Junglewise Threat Intelligence

CVE-2026-27877: Grafana information disclosure of data-source passwords in public dashboards

CVE-2026-27877 · Severity: medium · CVSS 6.5 · Published 2026-03-27

Vendors: Grafana Labs.

Executive brief

Grafana is a popular platform used for visualizing and monitoring data through dashboards. A security flaw in the 'public dashboards' feature allows unauthorized users to view the passwords of connected data sources if they are configured in 'direct' mode. This could allow an attacker to gain access to the underlying databases or services used by the organization, potentially leading to data theft or further network intrusion.

Technical details

An information disclosure vulnerability exists in Grafana's public dashboards feature. When a dashboard is made public and 'direct mode' data sources are configured, Grafana inadvertently exposes the credentials for all direct mode data sources in the environment, regardless of whether they are utilized by the public dashboard. This occurs because the application fails to properly filter or protect sensitive data-source metadata during the public session. The vulnerability does not affect 'proxied' data sources. Attackers with network access to a public dashboard can extract these credentials to gain unauthorized access to external databases. Patches are available in versions 11.6.14, 12.1.10, 12.2.8, 12.3.6, and 12.4.2.

Affected products

  • Grafana Labs Grafana <9.3.0, >=11.6.14 <12.0.0, >=12.1.10 <12.2.0, >=12.2.8 <12.3.0, >=12.3.6 <12.4.0, >=12.4.2

Timeline

  • 2026-03-27: disclosed
  • 2026-03-30: advisory
  • 2026-04-23: patched: Red Hat released updates for RHEL 9 and 10

References