Known Vulnerabilities for Grafana IRM by Grafana
Listed below are 10 of the newest known vulnerabilities associated with "Grafana IRM" by "Grafana".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-72585 json | An authorization bypass vulnerability in Grafana through 13.2.0 allows an Editor-role user to delete protected contact points... | Not Provided | 2026-08-10 | 2026-08-10 |
| CVE-2026-67342 json | ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Promet... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2026-63087 json | Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a vali... | Not Provided | 2026-07-16 | 2026-07-17 |
| CVE-2026-47671 json | Nhost is an open source Firebase alternative with GraphQL. In versions of Nhost CLI prior to 1.46.0, the hidden `nhost config... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-33382 json | Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. ... | Not Provided | 2026-07-10 | 2026-07-13 |
| CVE-2026-33380 json | A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesys... | Not Provided | 2026-05-13 | 2026-06-12 |
| CVE-2026-28381 json | The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data so... | Not Provided | 2026-06-22 | 2026-06-24 |
| CVE-2026-27878 json | A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amou... | Not Provided | 2026-06-19 | 2026-06-23 |
| CVE-2026-27876 json | A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RC... | Not Provided | 2026-03-27 | 2026-07-15 |
| CVE-2026-21723 json | The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with ... | Not Provided | 2026-07-23 | 2026-07-23 |