Vulnerability Details CVE-2026-42129
A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 31.7%
CVSS Severity
CVSS v3 Score 7.7
Products affected by CVE-2026-42129
-
cpe:2.3:a:grafana:loki_datasource:-