Vulnerabilities
Vulnerable Software
Grafana:  >> Grafana  >> 11.6.15  Security Vulnerabilities
In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role "Contact Point Writer", which is part of the basic role Editor - can edit contact points created by other users, modify the endpoint URL to a controlled server. By invoking the test functionality, attackers can capture and extract redacted secure settings, such as authentication credentials for third-party services (e.g., Slack tokens). This leads to unauthorized access and potential compromise of external integrations.
CVSS Score
1.3
EPSS Score
0.003
Published
2026-04-15
When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as possible to improve your deployments' security.
CVSS Score
6.5
EPSS Score
0.003
Published
2026-03-27
A resample query can be used to trigger out-of-memory crashes in Grafana.
CVSS Score
6.5
EPSS Score
0.004
Published
2026-03-27
The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes.
CVSS Score
7.5
EPSS Score
0.008
Published
2026-03-27
A testdata data-source can be used to trigger out-of-memory crashes in Grafana.
CVSS Score
6.5
EPSS Score
0.004
Published
2026-03-27


Contact Us

Shodan ® - All rights reserved