Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2558▼ 318 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

164 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (5.4)0.16%—GrafanaAI30/9/202630/9/2026
An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations) when creating a dashboard through the dashboard API, because these fields were stored without an authorization check. The dashboard then appears file-provisioned, and administrators…
Pendiente de análisisMedia (4.3)0.30%—GrafanaAI30/9/202630/9/2026
An authenticated user can list alert rules stored in folders they are not allowed to read through the alert rules API list endpoint. When the set of folders the user may read was empty, the folder restriction was dropped and every alert rule in the organization was returned. From Grafana 13.1.0, any user can trigger…
Pendiente de análisisAlta (7.3)0.35%—MaplibreAIGrafana GeomapAI17/9/202618/9/2026
A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user's session by hosting a malicious style configuration, enabling escalation to Org Admin.
Pendiente de análisisAlta (8.8)0.69%—Grafana OSSAIGrafana EnterpriseAI17/9/202619/9/2026
Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, writing arbitrary files and an executable backend binary outside that directory. The dropped…
Pendiente de análisisMedia (6.5)0.40%—GrafanaAIMicrosoft SQL ServerAIPostgresqlAIMysqlAI2/9/20263/9/2026
An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafana's regex-based macro parsing does not reject. Evaluating the injected macro causes uncontrolled memory consumption that can terminate the Grafana…
AnalizadaAlta (8.1)0.31%—Grafana2/9/202615/9/2026
Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who…
Pendiente de análisisMedia (6.8)0.27%—Grafana EnterpriseAI2/9/20263/9/2026
When SAML IdP-initiated login is enabled in Grafana Enterprise, the SAML library skips validation of the InResponseTo field on all SAML responses, including SP-initiated logins. This removes anti-replay protection, allowing an attacker who obtains a valid signed SAML assertion to replay it and gain a session as the…
Pendiente de análisisAlta (7.7)0.37%—Grafana AlloyAI27/8/202631/8/2026
Grafana Alloy’s prometheus.operator.servicemonitors component allows a user who can create or modify ServiceMonitor resources in a watched namespace to specify an arbitrary local file through bearerTokenFile. Alloy reads the file and sends its contents as a bearer token to an attacker-controlled scrape endpoint. This…
Pendiente de análisisMedia (6.3)0.15%—GrafanaAI26/8/202631/8/2026
A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot's secret delete key using only its public share key (broken access control).
Pendiente de análisisMedia (6.8)0.22%—GrafanaAI24/8/202631/8/2026
An authenticated attacker with Editor access or alert.instances.external:write can submit an external Alertmanager alert containing a controlled generatorURL. The attacker is authorized to create the alert, but not to execute script in another user's Grafana session. Grafana renders alert.generatorURL directly as the…
Pendiente de análisisAlta (7.1)0.31%—GrafanaAI19/8/202631/8/2026
An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a server-side expression while referencing a real datasource UID (incorrect authorization). This can expose data accessible through Grafana's configured datasource credentials…
Pendiente de análisisMedia (5.3)0.35%—GrafanaAI17/8/202631/8/2026
This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted. In a multi-organization stack, a user who is an Org Admin of a single organization can call GET /api/access-control/users/permissions/search?actionPrefix=dashboards: and receive…
Pendiente de análisisCrítica (9.1)0.31%—MCP GrafanaAI11/8/202631/8/2026
A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the caller also choose the HTTP method, path, and body. Because the destination is not restricted to the configured Grafana instance, a caller can direct requests at…
AplazadaMedia (5.3)0.33%—GrafanaAI23/7/202623/7/2026
The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anonymous access…
Pendiente de análisisCrítica (9.3)0.71%—Grafana OncallAI16/7/202617/7/2026
Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the internal plugin install endpoint using hardcoded default stack_id and org_id values present in the public source tree. Attackers can leverage…
Pendiente de análisisAlta (7.5)0.46%—Grafana LokiAI16/7/202616/7/2026
Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.
Pendiente de análisisAlta (8.6)0.53%—Grafana MCP ServerAI15/7/202615/7/2026
A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This also enables SSRF against arbitrary internal services, including cloud metadata endpoints.
AnalizadaAlta (7.5)0.48%—Grafana10/7/202613/7/2026
An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).
AnalizadaMedia (5.4)0.30%—Grafana10/7/202613/7/2026
A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting).
AnalizadaAlta (7.5)0.39%—Grafana10/7/202613/7/2026
Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.
AnalizadaBaja (2.7)0.23%—Grafana7/7/202610/7/2026
The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.
ModificadaAlta (7.5)0.43%—Grafana22/6/202610/7/2026
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication…
ModificadaMedia (5.4)0.32%—Grafana22/6/202610/7/2026
A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).
ModificadaAlta (7.7)0.44%—Grafana Loki Datasource22/6/202610/7/2026
A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.
AnalizadaAlta (8.1)0.35%—Grafana Snowflake22/6/202630/6/2026
The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write files between the local grafana server and the connected Snowflake host.