CVE-2026-27877
EUVD-2026-1659627.03.2026, 15:16
When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as possible to improve your deployments' security.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| grafana | grafana | 9.3.0 ≤ 𝑥 < 11.6.14 |
| grafana | grafana | 12.0.0 ≤ 𝑥 < 12.1.10 |
| grafana | grafana | 12.2.0 ≤ 𝑥 < 12.2.8 |
| grafana | grafana | 12.3.0 ≤ 𝑥 < 12.3.6 |
| grafana | grafana | 12.4.0 ≤ 𝑥 < 12.4.2 |
𝑥
= Vulnerable software versions