Grafana Alerting: Datasource query authorization bypass via spoofed queryType
High
| Advisory ID: | CVE-2026-17183 |
| Published: | 2026-08-24 |
| Product: | Grafana Enterprise |
| CVSS Score: | 7.1 |
| CVSS Vector: | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
| Fixed Versions: | <8.4.0 >=12.3.11 <12.4.0 >=12.4.9 <13.0.0 >=13.0.7 <13.1.0 >=13.1.4 <13.2.0 >=13.2.0 |
Summary
An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a server-side expression while referencing a real datasource UID (incorrect authorization). This can expose data accessible through Grafana’s configured datasource credentials to users who lack permission to query that datasource.