CVE-2026-42129
EUVD-2026-3824122.06.2026, 14:17
A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| grafana | loki_datasource | - |
𝑥
= Vulnerable software versions