{"api_version":"1","generated_at":"2026-09-19T07:47:16+00:00","cve":"CVE-2026-15815","urls":{"html":"https://cve.report/CVE-2026-15815","api":"https://cve.report/api/cve/CVE-2026-15815.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-15815","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-15815"},"summary":{"title":"CVE-2026-15815 CVE Record","description":"Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when\nextracting plugin archives. A crafted plugin archive can chain relative symbolic link\nentries to escape the plugin installation directory, writing arbitrary files and an\nexecutable backend binary outside that directory. The dropped executable runs with the\nprivileges of the Grafana server process, resulting in remote code execution.\n\nPlugin archives are extracted before their signature is verified, so a valid plugin\nsignature does not prevent the write. An operator can therefore be affected by\ninstalling a plugin that appears legitimate, as well as by installing a plugin from an\narbitrary archive using grafana-cli, the GF_INSTALL_PLUGINS environment variable, or\npreinstall configuration.\n\nGrafana Enterprise is affected because it includes the same plugin extraction code as\nGrafana OSS.","state":"PUBLISHED","assigner":"GRAFANA","published_at":"2026-09-17 21:17:11","updated_at":"2026-09-19 04:17:53"},"problem_types":["CWE-22","CWE-59","CWE-94","CWE-59 CWE-59","CWE-94 CWE-94","CWE-22 CWE-22"],"metrics":[{"version":"3.1","source":"security@grafana.com","type":"Secondary","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","data":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://grafana.com/security/security-advisories/cve-2026-15815","name":"https://grafana.com/security/security-advisories/cve-2026-15815","refsource":"security@grafana.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-15815","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-15815","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Grafana","product":"Grafana OSS","version":"affected 11.6.0 11.6.17 semver","platforms":[]},{"source":"CNA","vendor":"Grafana","product":"Grafana OSS","version":"affected 12.0.0 semver","platforms":[]},{"source":"CNA","vendor":"Grafana","product":"Grafana OSS","version":"affected 12.1.0 semver","platforms":[]},{"source":"CNA","vendor":"Grafana","product":"Grafana OSS","version":"affected 12.2.0 semver","platforms":[]},{"source":"CNA","vendor":"Grafana","product":"Grafana OSS","version":"affected 12.3.0 semver","platforms":[]},{"source":"CNA","vendor":"Grafana","product":"Grafana OSS","version":"affected 12.4.0 12.4.10 semver","platforms":[]},{"source":"CNA","vendor":"Grafana","product":"Grafana OSS","version":"affected 13.0.0 13.0.8 semver","platforms":[]},{"source":"CNA","vendor":"Grafana","product":"Grafana OSS","version":"affected 13.1.0 13.1.5 semver","platforms":[]},{"source":"CNA","vendor":"Grafana","product":"Grafana OSS","version":"affected 13.2.0 13.2.1 semver","platforms":[]},{"source":"CNA","vendor":"Grafana","product":"Grafana Enterprise","version":"affected 11.6.0 11.6.17 semver","platforms":[]},{"source":"CNA","vendor":"Grafana","product":"Grafana Enterprise","version":"affected 12.0.0 semver","platforms":[]},{"source":"CNA","vendor":"Grafana","product":"Grafana Enterprise","version":"affected 12.1.0 semver","platforms":[]},{"source":"CNA","vendor":"Grafana","product":"Grafana Enterprise","version":"affected 12.2.0 semver","platforms":[]},{"source":"CNA","vendor":"Grafana","product":"Grafana Enterprise","version":"affected 12.3.0 semver","platforms":[]},{"source":"CNA","vendor":"Grafana","product":"Grafana Enterprise","version":"affected 12.4.0 12.4.10 semver","platforms":[]},{"source":"CNA","vendor":"Grafana","product":"Grafana Enterprise","version":"affected 13.0.0 13.0.8 semver","platforms":[]},{"source":"CNA","vendor":"Grafana","product":"Grafana Enterprise","version":"affected 13.1.0 13.1.5 semver","platforms":[]},{"source":"CNA","vendor":"Grafana","product":"Grafana Enterprise","version":"affected 13.2.0 13.2.1 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"15815","cve":"CVE-2026-15815","epss":"0.008660000","percentile":"0.571020000","score_date":"2026-09-18","updated_at":"2026-09-19 00:06:15"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-15815","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-09-18T00:00:00+00:00","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-19T03:56:26.777Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Grafana OSS","vendor":"Grafana","versions":[{"lessThanOrEqual":"11.6.17","status":"affected","version":"11.6.0","versionType":"semver"},{"status":"affected","version":"12.0.0","versionType":"semver"},{"status":"affected","version":"12.1.0","versionType":"semver"},{"status":"affected","version":"12.2.0","versionType":"semver"},{"status":"affected","version":"12.3.0","versionType":"semver"},{"lessThanOrEqual":"12.4.10","status":"affected","version":"12.4.0","versionType":"semver"},{"lessThanOrEqual":"13.0.8","status":"affected","version":"13.0.0","versionType":"semver"},{"lessThanOrEqual":"13.1.5","status":"affected","version":"13.1.0","versionType":"semver"},{"lessThanOrEqual":"13.2.1","status":"affected","version":"13.2.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"Grafana Enterprise","vendor":"Grafana","versions":[{"lessThanOrEqual":"11.6.17","status":"affected","version":"11.6.0","versionType":"semver"},{"status":"affected","version":"12.0.0","versionType":"semver"},{"status":"affected","version":"12.1.0","versionType":"semver"},{"status":"affected","version":"12.2.0","versionType":"semver"},{"status":"affected","version":"12.3.0","versionType":"semver"},{"lessThanOrEqual":"12.4.10","status":"affected","version":"12.4.0","versionType":"semver"},{"lessThanOrEqual":"13.0.8","status":"affected","version":"13.0.0","versionType":"semver"},{"lessThanOrEqual":"13.1.5","status":"affected","version":"13.1.0","versionType":"semver"},{"lessThanOrEqual":"13.2.1","status":"affected","version":"13.2.0","versionType":"semver"}]}],"datePublic":"2026-08-15T11:19:01.400Z","descriptions":[{"lang":"en","value":"Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when\nextracting plugin archives. A crafted plugin archive can chain relative symbolic link\nentries to escape the plugin installation directory, writing arbitrary files and an\nexecutable backend binary outside that directory. The dropped executable runs with the\nprivileges of the Grafana server process, resulting in remote code execution.\n\nPlugin archives are extracted before their signature is verified, so a valid plugin\nsignature does not prevent the write. An operator can therefore be affected by\ninstalling a plugin that appears legitimate, as well as by installing a plugin from an\narbitrary archive using grafana-cli, the GF_INSTALL_PLUGINS environment variable, or\npreinstall configuration.\n\nGrafana Enterprise is affected because it includes the same plugin extraction code as\nGrafana OSS."}],"metrics":[{"cvssV3_1":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-59","description":"CWE-59","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-94","description":"CWE-94","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-22","description":"CWE-22","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-17T20:47:01.006Z","orgId":"57da9224-a3e2-4646-9d0e-c4dc2e05e7da","shortName":"GRAFANA"},"references":[{"tags":["vendor-advisory"],"url":"https://grafana.com/security/security-advisories/cve-2026-15815"}],"source":{"discovery":"INTERNAL_FINDING"},"title":"CVE-2026-15815 CVE Record","x_generator":{"engine":"cvelib 1.8.0"}}},"cveMetadata":{"assignerOrgId":"57da9224-a3e2-4646-9d0e-c4dc2e05e7da","assignerShortName":"GRAFANA","cveId":"CVE-2026-15815","datePublished":"2026-09-17T20:47:01.006Z","dateReserved":"2026-07-15T11:15:50.200Z","dateUpdated":"2026-09-19T03:56:26.777Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-17 21:17:11","lastModifiedDate":"2026-09-19 04:17:53","problem_types":["CWE-22","CWE-59","CWE-94","CWE-59 CWE-59","CWE-94 CWE-94","CWE-22 CWE-22"],"metrics":{"cvssMetricV31":[{"source":"security@grafana.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-18T00:00:00+00:00","id":"CVE-2026-15815","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"15815","Ordinal":"1","Title":"CVE-2026-15815 CVE Record","CVE":"CVE-2026-15815","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"15815","Ordinal":"1","NoteData":"Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when\nextracting plugin archives. A crafted plugin archive can chain relative symbolic link\nentries to escape the plugin installation directory, writing arbitrary files and an\nexecutable backend binary outside that directory. The dropped executable runs with the\nprivileges of the Grafana server process, resulting in remote code execution.\n\nPlugin archives are extracted before their signature is verified, so a valid plugin\nsignature does not prevent the write. An operator can therefore be affected by\ninstalling a plugin that appears legitimate, as well as by installing a plugin from an\narbitrary archive using grafana-cli, the GF_INSTALL_PLUGINS environment variable, or\npreinstall configuration.\n\nGrafana Enterprise is affected because it includes the same plugin extraction code as\nGrafana OSS.","Type":"Description","Title":"CVE-2026-15815 CVE Record"}]}}}