CVE 5 MEDIUM

CVE-2026-22641_CVE-2026-22641

5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Description

This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources. The issue primarily affects datasources that implement route-specific permissions, including Alertmanager and certain Prometheus-based datasources.

Basic Information

ID CVE-2026-22641
Source SICK AG
Published Jan 15, 2026 at 13:13

Affected Product

Vendor SICK AG
Product Incoming Goods Suite
Affected Versions SICK AG Incoming Goods Suite 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.