SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-17183

HIGH · CVSS 7.1 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Authenticated users with permission to create or edit alert rules in Grafana can exploit a flaw that allows them to bypass datasource query authorization by designating an alert rule query as a server-side expression. This vulnerability can lead to unauthorized access to sensitive data through the configured datasource credentials, potentially exposing information to users without the necessary permissions. Organizations using Grafana should prioritize addressing this issue to protect their data integrity and prevent unauthorized data exposure.

CVE
CVE-2026-17183
Severity
HIGH
CVSS
7.1
EPSS
0.29%

Original NVD Description

An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a server-side expression while referencing a real datasource UID (incorrect authorization). This can expose data accessible through Grafana's configured datasource credentials to users who lack permission to query that datasource.