Missing Authorization in Grafana - CVE-2026-13719
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote user to disclose alert rule configuration.
The vulnerability exists due to improper authorization in the alert rules API list endpoint when the set of folders the user may read is empty. A remote user can request alert rules through the list endpoint to disclose alert rule configuration.
Data source credentials are not exposed.