Link following in Grafana Enterprise - CVE-2026-15815

 

Link following in Grafana Enterprise - CVE-2026-15815

Published: September 30, 2026


Vulnerability identifier: #VU152980
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-15815
CWE-ID: CWE-59
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper link resolution in plugin archive extraction when extracting a crafted plugin archive. A remote attacker can provide a crafted plugin archive containing chained relative symbolic links to write files and an executable backend binary outside the plugin installation directory to execute arbitrary code.

User interaction is required to install the crafted plugin archive. Plugin archives are extracted before their signatures are verified.


Affected software

Grafana Enterprise

How to mitigate CVE-2026-15815

Install security update from vendor's website.

Grafana Enterprise - addressed in versions 12.4.11, 13.0.9, 13.1.6, 13.2.2

External References

Related Security Bulletins