๐Ÿ” CVE Alert

CVE-2026-21726

MEDIUM 5.3

Loki Path Traversal - CVE-2021-36156 Bypass

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by double encoding, an attacker can read files at the Ruler API endpoint /loki/api/v1/rules/{namespace} Thanks to Prasanth Sundararajan for reporting this vulnerability.

Vendor grafana
Product loki
Ecosystems
Industries
Technology
Published Apr 15, 2026
Last Updated Apr 15, 2026
Stay Ahead of the Next One

Get instant alerts for grafana loki

Be the first to know when new medium vulnerabilities affecting grafana loki are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Grafana / Loki
2.3.0 < 3.5.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
grafana.com: https://grafana.com/security/security-advisories/cve-2026-21726