🔐 CVE Alert

CVE-2026-15815

HIGH 8.8

CVE-2026-15815 CVE Record

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, writing arbitrary files and an executable backend binary outside that directory. The dropped executable runs with the privileges of the Grafana server process, resulting in remote code execution. Plugin archives are extracted before their signature is verified, so a valid plugin signature does not prevent the write. An operator can therefore be affected by installing a plugin that appears legitimate, as well as by installing a plugin from an arbitrary archive using grafana-cli, the GF_INSTALL_PLUGINS environment variable, or preinstall configuration. Grafana Enterprise is affected because it includes the same plugin extraction code as Grafana OSS.

CWE CWE-59 CWE-94 CWE-22
Vendor grafana
Product grafana oss
Ecosystems
Industries
Technology
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for grafana grafana oss

Be the first to know when new high vulnerabilities affecting grafana grafana oss are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Grafana / Grafana OSS
11.6.0 ≤ 11.6.17 12.0.0 12.1.0 12.2.0 12.3.0 12.4.0 ≤ 12.4.10 13.0.0 ≤ 13.0.8 13.1.0 ≤ 13.1.5 13.2.0 ≤ 13.2.1
Grafana / Grafana Enterprise
11.6.0 ≤ 11.6.17 12.0.0 12.1.0 12.2.0 12.3.0 12.4.0 ≤ 12.4.10 13.0.0 ≤ 13.0.8 13.1.0 ≤ 13.1.5 13.2.0 ≤ 13.2.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
grafana.com: https://grafana.com/security/security-advisories/cve-2026-15815