Known Vulnerabilities for Grafana OSS by Grafana
Listed below are 10 of the newest known vulnerabilities associated with "Grafana OSS" by "Grafana".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-75889 json | Grafana Alloy’s prometheus.operator.servicemonitors component allows a user who can create or modify ServiceMonitor resourc... | Not Provided | 2026-08-27 | 2026-08-28 |
| CVE-2026-71366 json | A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Mattermost, ... | Not Provided | 2026-08-24 | 2026-08-26 |
| CVE-2026-67342 json | ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Promet... | Not Provided | 2026-08-01 | 2026-08-03 |
| CVE-2026-63087 json | Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a vali... | Not Provided | 2026-07-16 | 2026-07-17 |
| CVE-2026-47671 json | Nhost is an open source Firebase alternative with GraphQL. In versions of Nhost CLI prior to 1.46.0, the hidden `nhost config... | Not Provided | 2026-07-21 | 2026-07-22 |
| CVE-2026-33382 json | Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. ... | Not Provided | 2026-07-10 | 2026-07-13 |
| CVE-2026-28381 json | The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data so... | Not Provided | 2026-06-22 | 2026-06-24 |
| CVE-2026-27878 json | A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amou... | Not Provided | 2026-06-19 | 2026-06-23 |
| CVE-2026-27876 json | A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RC... | Not Provided | 2026-03-27 | 2026-07-15 |
| CVE-2026-21727 json | A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records. Du... | Not Provided | 2026-04-15 | 2026-08-19 |