CVE 6.5 MEDIUM

Public dashboards discloses all direct mode datasources_CVE-2026-27877

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Description

When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards.

No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as possible to improve your deployments' security.

Basic Information

ID CVE-2026-27877
Source GRAFANA
Published Mar 27, 2026 at 14:02
Modified Apr 9, 2026 at 13:49

Affected Product

Vendor Grafana
Product Grafana
Version 9.3.0
Affected Versions Grafana Grafana 9.3.0
Grafana Grafana 12.0.0
Grafana Grafana 12.2.0
Grafana Grafana 12.3.0
Grafana Grafana 12.4.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.