CVE-2026-17183

Aliases:UBUNTU-CVE-2026-17183CGA-2fr8-3g49-g3w9CGA-2fxh-wp6w-fqmgCGA-2vrg-xhx8-767wCGA-33vg-wf9q-rcg6CGA-3636-4rhw-4h37CGA-3g3m-hffx-v23wCGA-4f4w-jxv9-p888CGA-543p-439f-34c5CGA-55x8-8cv8-qhr6CGA-5mq7-29fp-77j8CGA-5pp8-2j25-f7q2CGA-6v36-jjwx-4452CGA-6xfj-pfwh-hfqrCGA-7242-vxxq-3w3vCGA-78cc-433f-5vqhCGA-8cpw-j29h-r5f4CGA-8jr6-jf3g-hx7jCGA-8r5v-2q3p-79rfCGA-8rq9-mqq5-j4q9CGA-9479-55r6-4vhcCGA-9m9q-xhcm-4gx6CGA-cfmq-mvpq-4fc3CGA-ch3p-rvfq-vr8jCGA-cqqg-m836-h39gCGA-gv65-89mq-h5q2CGA-h2rx-fp32-q5w6CGA-h2xp-jf57-6cmjCGA-hmgw-wh62-82r6CGA-j3jv-5496-87hjCGA-jrmf-rf2h-9j64CGA-jvc7-46wv-fj28CGA-m36w-8p35-hc4vCGA-m37r-hh76-mcvhCGA-mfwc-f5p3-hr5hCGA-mrmh-4499-32cvCGA-mw69-6m7w-3rqhCGA-p4mh-4233-pr8mCGA-p9c3-x74m-g3p7CGA-r2rh-28r8-c8wxCGA-v8jc-c9r6-9v3cCGA-vx4x-j7q4-qf5cCGA-wfxw-ghwg-7x9vCGA-f73w-cx3f-hc8cCGA-g6rf-r468-49gfCGA-h377-4356-fq6cCGA-hq69-532q-h7x5CGA-qfg9-mpfh-5jw5CGA-xx3p-fwcj-wm87
Advisory lineage Upstream: 0 Downstream: 1
Awaiting Analysis
Published: 19 Aug 2026, 17:30
Last modified:27 Aug 2026, 17:22

Vulnerability Summary

Overall Risk (default)
medium
28/100
CVSS Score
7.1 HIGH
v3.1 (cve.org)
EPSS Score
0.29% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

19 Aug 2026, 17:30
Published
Vulnerability first disclosed
27 Aug 2026, 17:22
Last Modified
Vulnerability information updated

Description

An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a server-side expression while referencing a real datasource UID (incorrect authorization). This can expose data accessible through Grafana's configured datasource credentials to users who lack permission to query that datasource.

CVSS Metrics

  • v3.1HIGHScore: 7.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

EPSS Trends

Current EPSS score: 0.29% Percentile: 21%

Techniques & Countermeasures

  • CWE-863Incorrect Authorization

    The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Affected Systems

  • chainguardgrafana-11.6

    all

  • chainguardgrafana-12.1

    all

  • chainguardgrafana-12.2

    all

  • chainguardgrafana-fips-11.6

    all

  • chainguardgrafana-fips-12.1

    all

  • chainguardgrafana-fips-12.2

    all

  • chainguardpercona-grafana

    all

  • ubuntugrafana

    all

  • grafanagrafana enterprise

    ≥ 8.4.0, < 12.3.11 | ≥ 12.4.0, < 12.4.9 | ≥ 13.0.0, < 13.0.7 | ≥ 13.1.0, < 13.1.4

  • grafanagrafana oss

    ≥ 8.4.0, ≤ 13.1.1 | ≥ 8.4.0, < 12.3.11 | ≥ 12.4.0, < 12.4.9 | ≥ 13.0.0, < 13.0.7 | ≥ 13.1.0, < 13.1.4

References (3)