CVE-2026-17183EPSS p21.4%
CVE-2026-17183CVE-2026-17183
Description
An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a server-side expression while referencing a real datasource UID (incorrect authorization). This can expose data accessible through Grafana's configured datasource credentials to users who lack permission to query that datasource.
Scoring
| CVSS | 7.1 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
| EPSS | 0.31% probability of exploitation · percentile 21.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-08-31 |