Missing Authorization in Grafana - CVE-2026-13719

 

Missing Authorization in Grafana - CVE-2026-13719

Published: October 1, 2026


Vulnerability identifier: #VU153114
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-13719
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose alert rule configuration.

The vulnerability exists due to improper authorization in the alert rules API list endpoint when the set of folders the user may read is empty. A remote user can request alert rules through the list endpoint to disclose alert rule configuration.

Data source credentials are not exposed.


Affected software

Grafana

How to mitigate CVE-2026-13719

Install security update from vendor's website.

Grafana - addressed in versions 12.4.12, 13.0.10, 13.1.7, 13.2.3

External References

Related Security Bulletins