SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2026-10601

Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative actions on the configured backend.

MEDIUM 4.3EPSS 0.29%

Does this matter?

Lower severity and a low EPSS score (0.29%). Track it; it rarely justifies an emergency change on its own.

Description

A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative actions on the configured backend.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
0.29% probability · 21th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
grafana/grafana
Source
security@grafana.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.