Medium severity5.4NVD Advisory· Published Jun 22, 2026· Updated Jul 10, 2026
CVE-2026-10601
CVE-2026-10601
Description
A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative actions on the configured backend.
Affected products
3Patches
Vulnerability mechanics
References
1- grafana.com/security/security-advisories/cve-2026-10601nvdBroken Link
News mentions
0No linked articles in our index yet.