SB2026093089 - Link following in Grafana Enterprise
Published: September 30, 2026 Updated: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Link following (CVE-ID: CVE-2026-15815)
CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper link resolution in plugin archive extraction when extracting a crafted plugin archive. A remote attacker can provide a crafted plugin archive containing chained relative symbolic links to write files and an executable backend binary outside the plugin installation directory to execute arbitrary code.
User interaction is required to install the crafted plugin archive. Plugin archives are extracted before their signatures are verified.
Remediation
Install update from vendor's website.