#VU124711 Information disclosure in Grafana - CVE-2026-27877
Published: March 31, 2026
Grafana
Grafana Labs
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in public dashboards when handling direct mode data sources. A remote user can access publicly shared dashboards to disclose sensitive information.
Authentication is required to create or access public dashboards; only direct mode data sources are affected.