CVE-2026-28379

Aliases:CGA-2r6x-g5q9-h468CGA-6895-fw34-qcf2CGA-8rfg-fvg5-65c7CGA-f96p-ch7g-8695CGA-h9w9-x8x8-jv98CGA-jw4g-8mcq-xwvjCGA-pjgg-cq4x-75pgCGA-22c3-6229-fxq8CGA-2xrg-qg3q-qf97CGA-33q5-7vhm-x27xCGA-3j4q-pp5x-mjpcCGA-4f76-67mr-ff4pCGA-4hqw-3v6v-gvwrCGA-57j3-fr28-64j7CGA-5cjg-28v9-6m9vCGA-7996-wmv2-r6mrCGA-87fp-jg3g-5x4cCGA-8jhv-gc8f-4324CGA-8w6f-5vw2-859vCGA-95mj-vqmp-4g3pCGA-95mq-jg76-694gCGA-9r3q-9j4p-4j5vCGA-9r9h-3ph4-x8vcCGA-c37h-mqgq-h65xCGA-cp4j-v4pm-wf25CGA-g6mh-h9v2-5fm2CGA-h9jh-hm7j-323hCGA-jr49-c285-6689CGA-jwfc-pxpx-636wCGA-mm79-mgvq-g83jCGA-p5jg-fg63-pmwxCGA-prpw-xg6c-vv9fCGA-q546-4q6p-rfh8CGA-q564-9w3v-w83hCGA-q8v3-3x26-x39wCGA-r6j9-vr2h-8q7jCGA-rx4g-4r9j-g263CGA-vj6j-wpvg-5xj8CGA-w269-4c35-hm8cCGA-w6w9-3jx7-4v7jCGA-xc76-cqm7-pggxCGA-xr5w-4wrq-6v83
Analyzed
Published: 13 May 2026, 19:28
Last modified:27 Aug 2026, 17:22

Vulnerability Summary

Overall Risk (default)
medium
26/100
CVSS Score
6.5 MEDIUM
v3.1 (cve.org)
EPSS Score
0.26% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

13 May 2026, 19:28
Published
Vulnerability first disclosed
27 Aug 2026, 17:22
Last Modified
Vulnerability information updated

Description

A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server crash by sending concurrent requests that cause a fatal map access error. This results in complete service unavailability requiring restart of the Grafana server.

CVSS Metrics

  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.26% Percentile: 18%

Techniques & Countermeasures

  • CWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

    The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

Affected Systems

  • chainguardgrafana-12.0

    all

  • chainguardgrafana-12.1

    all

  • chainguardgrafana-12.4

    < 12.4.3.02-r0

  • chainguardgrafana-fips-12.0

    all

  • chainguardgrafana-fips-12.1

    all

  • chainguardgrafana-fips-12.4

    < 12.4.4-r0

  • wolfigrafana-12.4

    < 12.4.3.02-r0

  • grafanagrafana

    ≥ 8.5.0, < 11.6.14 | ≥ 12.2.0, < 12.2.8 | ≥ 12.3.0, < 12.3.6 | ≥ 12.4.0, < 12.4.3 | 11.6.14 | 11.6.14:security01 | 12.2.8 | 12.2.8:security01 | 12.3.6 | 12.3.6:security01 | 12.4.3 | 13.0.0 | 13.0.1

  • grafanagrafana oss

    ≥ 8.2.0, ≤ 11.6.14 | ≥ 11.6.14, < 11.6.14+security-04 | ≥ 12.0.0, ≤ 12.2.8 | ≥ 12.2.8, < 12.2.8+security-04 | ≥ 12.3.0, ≤ 12.3.6 | ≥ 12.3.6, < 12.3.6+security-04 | ≥ 12.4.0, ≤ 12.4.3 | ≥ 12.4.3, < 12.4.3+security-02 | ≥ 13.0.0, ≤ 13.0.1 | ≥ 13.0.1, < 13.0.1+security-01

References (3)