#VU126254 Improper access control in Grafana - CVE-2025-12141
Published: April 15, 2026
Grafana
Grafana Labs
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in contact points in Grafana alerting when invoking the test functionality after modifying the endpoint URL. A remote user can modify a contact point created by another user and trigger a test request to disclose sensitive information.
The issue can expose redacted secure settings such as authentication credentials for third-party services.