High severity7.1NVD Advisory· Published Aug 19, 2026· Updated Aug 31, 2026
CVE-2026-17183
CVE-2026-17183
Description
An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a server-side expression while referencing a real datasource UID (incorrect authorization). This can expose data accessible through Grafana's configured datasource credentials to users who lack permission to query that datasource.
Affected products
3- osv-coords2 versions
>= 8.4.0, < 12.3.11+ 1 more
- (no CPE)range: >= 8.4.0, < 12.3.11
- (no CPE)range: < 12.4.10-1.1
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.