OPENSUSE-SU-2026:20940-1

Advisory lineage Upstream: 24 Downstream: 0
Published: 10 Jun 2026, 12:02
Last modified:13 Jun 2026, 18:24

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

10 Jun 2026, 12:02
Published
Vulnerability first disclosed
13 Jun 2026, 18:24
Last Modified
Vulnerability information updated

Description

Security update for grafana This update for grafana fixes the following issues: Changes in grafana: - CVE-2026-39821: Fix validation bypass and privilege escalation by updating golang.org/x/net to version 0.55.0 (bsc#1266600) - Update to version 11.6.14+security-04: Security: * CVE-2026-28374: Fix insecure direct object reference in Annotations API (bsc#1265290) * CVE-2026-28376: Fix unbounded memory allocation in Grafana Live push endpoint (bsc#1265289) * CVE-2026-28383: Fix unbounded memory allocation in Grafana plugin resources (bsc#1265286) * CVE-2026-28380: Fix broken access control in Snapshot API (bsc#1265287) * CVE-2026-33376: Fix Auth Proxy IPv6 whitelist bypass (bsc#1265285) * CVE-2026-28379: Fix viewer-triggered race condition in Grafana Live (bsc#1265288) * CVE-2026-33377: Fix dashboard Editor Privilege Escalation (bsc#1265284) * CVE-2026-33378: Fix OOM exception in Grafana Data Source Plugin (bsc#1265283) * CVE-2026-33381: Prevent users from generating Service Account tokens after permissions removal (bsc#1265281) * CVE-2026-33380: Fix vulnerability in SQL Expressions allowing an authenticated attacker to read arbitrary files from the Grafana server’s filesystem (bsc#1265282) - CVE-2026-34986: Fix panic in JWE decryption (bsc#1262950) - CVE-2026-41602: Fix Integer Overflow or Wraparound vulnerability in Apache Thrift (bsc#1263501) - CVE-2026-26958: Bump filippo.io/edwards25519 to version 1.1.1 (bsc#1258595) - CVE-2026-21725: Fix missing UID when deleting datasource by name (bsc#1258873) - Update to version 11.6.14+security-01: Security: * CVE-2026-33375: Fix denial of Service via out-of-memory exhaustion in MSSQL data source plugin (bsc#1260881) - Update to version 11.6.14: Security: * CVE-2026-27876: Fix remote arbitrary code execution via chained SQL Expressions (bsc#1261025) * CVE-2026-27877: Fix information disclosure of data-source passwords via public dashboards (bsc#1261026) * CVE-2026-28375: Fix denial of service via testdata data-source (bsc#1261029) * CVE-2026-27879: Fix denial of service via resample query (bsc#1261027) * CVE-2026-33186: Fix authorization bypass due to improper validation of the HTTP/2 :path pseudo-header (bsc#1260263) * CVE-2026-21724: Fix authorization bypass allows modification of protected webhook URLs (bsc#1260878) - Update to version 11.6.13: Enhancement: * Wire the public dashboard service to the HTTP server - Update to version 11.6.12: Enhancement: * Update authentication redirect logic Bug fix: * Fix single panel render with variable references

Affected Systems

  • opensusegrafana&distro=openSUSE Leap 16.0

    < 11.6.14+security04-bp160.1.1

References (48)