Link following in Grafana Enterprise - CVE-2026-15815
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper link resolution in plugin archive extraction when extracting a crafted plugin archive. A remote attacker can provide a crafted plugin archive containing chained relative symbolic links to write files and an executable backend binary outside the plugin installation directory to execute arbitrary code.
User interaction is required to install the crafted plugin archive. Plugin archives are extracted before their signatures are verified.