6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Description
When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards.
No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as possible to improve your deployments' security.
No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as possible to improve your deployments' security.
Basic Information
ID
CVE-2026-27877
Source
GRAFANA
Published
Mar 27, 2026 at 14:02
Modified
Apr 9, 2026 at 13:49
Affected Product
Vendor
Grafana
Product
Grafana
Version
9.3.0
Affected Versions
Grafana Grafana 9.3.0
Grafana Grafana 12.0.0
Grafana Grafana 12.2.0
Grafana Grafana 12.3.0
Grafana Grafana 12.4.0
Grafana Grafana 12.0.0
Grafana Grafana 12.2.0
Grafana Grafana 12.3.0
Grafana Grafana 12.4.0