๐Ÿ” CVE Alert

CVE-2026-63199

UNKNOWN 0.0

Perses: Missing authorization in datasource proxy allows cross-scope secret disclosure

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Perses is an open-source dashboard and visualization project for observability data. From 0.43.0 until 0.54.0-rc.0, the datasource creation and unsaved datasource proxy paths authorize the caller on a Datasource or GlobalDatasource scope but do not require read permission for the separately grantable associated project or global Secret before resolving it. A low-privilege user with GlobalDatasource:create or corresponding project datasource creation rights can attach a project or global Secret that the user cannot otherwise read, point the datasource at a service controlled by the user, and cause Perses to send the decrypted secret in plaintext, bypassing project and global scope separation. This issue is fixed in version 0.54.0-rc.0.

CWE CWE-862
Vendor perses
Product perses
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for perses perses

Be the first to know when new unknown vulnerabilities affecting perses perses are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

perses / perses
>= 0.43.0, < 0.54.0-rc.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/perses/perses/security/advisories/GHSA-4227-9989-jrhx github.com: https://github.com/perses/perses/commit/2368c9ef4eb0a70fbca5df69aa20e595821ab625 github.com: https://github.com/perses/perses/releases/tag/v0.54.0-rc.0