SB2026093089 - Link following in Grafana Enterprise



SB2026093089 - Link following in Grafana Enterprise

Published: September 30, 2026 Updated: September 30, 2026

Security Bulletin ID SB2026093089
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Link following (CVE-ID: CVE-2026-15815)

CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper link resolution in plugin archive extraction when extracting a crafted plugin archive. A remote attacker can provide a crafted plugin archive containing chained relative symbolic links to write files and an executable backend binary outside the plugin installation directory to execute arbitrary code.

User interaction is required to install the crafted plugin archive. Plugin archives are extracted before their signatures are verified.


Remediation

Install update from vendor's website.