Vulnerabilidades em grafana
122 resultadosAnálise Vexday
Grafana apresenta 30 vulnerabilidades catalogadas, das quais 2 estão sob ataque ativo e 3 são críticas, configurando risco material para ambientes em produção. A fraqueza dominante é exposição de informações (CWE-200), típica de produtos web, embora nenhuma vulnerabilidade tenha sido publicada nos últimos 90 dias, sugerindo que o risco atual é estável e não inclui ameaças zero-day recentes.
CVE-2026-12704MEDIUMSAML assertion replay via skipped InResponseTo validationEPSS 0.3%CVE-2022-31123MEDIUMGrafana plugin signature bypass vulnerabilityEPSS 0.3%CVE-2024-8996HIGHGrafana Agent Flow on Windows Unquoted service pathEPSS 0.3%CVE-2026-21724MEDIUMMissing Protected-field Authorization in Provisioning Contact Points APIEPSS 0.3%CVE-2026-28379MEDIUMViewer-triggered race condition in Grafana Live leads to complete server crashEPSS 0.3%CVE-2026-11817MEDIUMCVE-2026-11817 CVE RecordEPSS 0.3%CVE-2025-12141LOWGrafana Alerting Editors can edit destination of webhooks they did not createEPSS 0.3%CVE-2026-9029HIGHStored XSS in the Geomap panel tile-layer attributionEPSS 0.3%CVE-2025-41117MEDIUMXSS in Grafana Explore stack traceEPSS 0.2%CVE-2026-19516CRITICALCVE-2026-19516 CVE RecordEPSS 0.2%CVE-2026-8595MEDIUMStored XSS in the table panel (TableNG)EPSS 0.2%CVE-2026-28378LOWCross-Organization Public Dashboard Deletion via Missing Org IsolationEPSS 0.2%CVE-2026-28380MEDIUMBAC in Snapshot API allows deletion of unauthorized dashboard snapshotsEPSS 0.2%CVE-2026-33377HIGHDashboard Import Overwrites ACL — Editor Privilege Escalation to Dashboard AdminEPSS 0.2%CVE-2026-75889HIGHCVE-2026-75889 CVE RecordEPSS 0.2%CVE-2026-17033MEDIUMCVE-2026-17033 CVE RecordEPSS 0.2%CVE-2026-21727LOWGrafana Correlations: Cross-Tenant Data Disclosure and Permanent Deletion via Legacy org_id=0 RecordEPSS 0.2%CVE-2026-19197MEDIUMBroken access control in dashboard snapshotsEPSS 0.2%CVE-2026-28374MEDIUMIDOR in Annotations API allows unprivileged users to DELETE annotationEPSS 0.2%CVE-2026-21725LOWAuthorization Bypass via TOCTOU in Grafana Datasource Deletion by NameEPSS 0.2%