Junglewise Threat Intelligence

CVE-2026-63087: Grafana OnCall authentication bypass in plugin install endpoint

CVE-2026-63087 · Severity: critical · CVSS 9.8 · Published 2026-07-16

Vendors: Grafana.

Executive brief

Grafana OnCall is an incident response tool used to manage on-call rotations and alerts. A security flaw allows unauthorized individuals to gain full administrative control over the system by exploiting a weakness in how the software handles plugin installations. An attacker could use this access to steal sensitive data, create new administrator accounts, or redirect communications to a malicious server, potentially disrupting emergency response operations.

Technical details

An unauthenticated access vulnerability (CWE-306) exists in Grafana OnCall through version 1.16.11 due to a lack of authentication on the internal plugin installation endpoint. By sending a POST request to '/api/internal/v1/plugin/v2/install/' using hardcoded 'stack_id' and 'org_id' values found in the public source tree, a remote attacker can obtain a valid 'PluginAuthToken'. This token grants access to all internal API endpoints. Attackers can subsequently create arbitrary Admin users via the user-context header bootstrap path, revoke legitimate tokens, and hijack OnCall-to-Grafana communications by overwriting the 'grafana_url' and 'api_token' settings. The repository was archived in June 2026, and no official patch is currently noted.

Affected products

  • Grafana OnCall through 1.16.11

Timeline

  • 2026-06-05: other: Repository archived by owner
  • 2026-07-16: advisory: CVE published to NVD

References