CVE-2026-21723
CVE-2026-21723 Record
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anonymous access enabled.
| Vendor | grafana |
| Product | grafana oss |
| Ecosystems | |
| Industries | Technology |
| Published | Jul 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for grafana grafana oss
Be the first to know when new medium vulnerabilities affecting grafana grafana oss are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Grafana / Grafana OSS
8.0.0 ≤ 11.0.0 11.0.0 ≤ 11.6.10 12.0.0 ≤ 12.0.9 12.1.0 ≤ 12.1.6 12.2.0 ≤ 12.2.4 12.3.0 ≤ 12.3.2
References
Credits
nacl (Researcher)