Vulnerability Description
A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative actions on the configured backend.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Grafana | Grafana | 11.6.0 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-10601?
CVE-2026-10601 is a vulnerability with a CVSS score of 5.4 (MEDIUM). A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expos...
How severe is CVE-2026-10601?
CVE-2026-10601 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-10601?
Check the references section above for vendor advisories and patch information. Affected products include: Grafana Grafana.