By vendor

Grafana vulnerabilities

Known CVEs affecting Grafana products, prioritized by severity, with SEC.co remediation and detection guidance.

1 published vulnerability

  • CVE-2026-11769HIGH 8.8

    The Grafana Operator, a popular tool for managing Grafana instances in Kubernetes environments, contains a security flaw that allows attackers with dashboard creation permissions to steal the operator's service account token. The vulnerability stems from the operator's support for jsonnet templating—a data definition language evaluated within the operator's pod context—which can be exploited to access sensitive credentials. This affects all versions up to and including 5.23, with version 5.24.0 providing the fix.