CVE-2026-15815 CVE Record
Summary
| CVE | CVE-2026-15815 |
|---|---|
| State | PUBLISHED |
| Assigner | GRAFANA |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-17 21:17:11 UTC |
| Updated | 2026-09-19 04:17:53 UTC |
| Description | Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, writing arbitrary files and an executable backend binary outside that directory. The dropped executable runs with the privileges of the Grafana server process, resulting in remote code execution. Plugin archives are extracted before their signature is verified, so a valid plugin signature does not prevent the write. An operator can therefore be affected by installing a plugin that appears legitimate, as well as by installing a plugin from an arbitrary archive using grafana-cli, the GF_INSTALL_PLUGINS environment variable, or preinstall configuration. Grafana Enterprise is affected because it includes the same plugin extraction code as Grafana OSS. |
Risk And Classification
Primary CVSS: v3.1 8.8 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS: 0.008660000 probability, percentile 0.571020000 (date 2026-09-18)
Problem Types: CWE-22 | CWE-59 | CWE-94 | CWE-59 CWE-59 | CWE-94 CWE-94 | CWE-22 CWE-22
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Grafana | Grafana OSS | affected 11.6.0 11.6.17 semver | Not specified |
| CNA | Grafana | Grafana OSS | affected 12.0.0 semver | Not specified |
| CNA | Grafana | Grafana OSS | affected 12.1.0 semver | Not specified |
| CNA | Grafana | Grafana OSS | affected 12.2.0 semver | Not specified |
| CNA | Grafana | Grafana OSS | affected 12.3.0 semver | Not specified |
| CNA | Grafana | Grafana OSS | affected 12.4.0 12.4.10 semver | Not specified |
| CNA | Grafana | Grafana OSS | affected 13.0.0 13.0.8 semver | Not specified |
| CNA | Grafana | Grafana OSS | affected 13.1.0 13.1.5 semver | Not specified |
| CNA | Grafana | Grafana OSS | affected 13.2.0 13.2.1 semver | Not specified |
| CNA | Grafana | Grafana Enterprise | affected 11.6.0 11.6.17 semver | Not specified |
| CNA | Grafana | Grafana Enterprise | affected 12.0.0 semver | Not specified |
| CNA | Grafana | Grafana Enterprise | affected 12.1.0 semver | Not specified |
| CNA | Grafana | Grafana Enterprise | affected 12.2.0 semver | Not specified |
| CNA | Grafana | Grafana Enterprise | affected 12.3.0 semver | Not specified |
| CNA | Grafana | Grafana Enterprise | affected 12.4.0 12.4.10 semver | Not specified |
| CNA | Grafana | Grafana Enterprise | affected 13.0.0 13.0.8 semver | Not specified |
| CNA | Grafana | Grafana Enterprise | affected 13.1.0 13.1.5 semver | Not specified |
| CNA | Grafana | Grafana Enterprise | affected 13.2.0 13.2.1 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| grafana.com/security/security-advisories/cve-2026-15815 | [email protected] | grafana.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.