PT-2026-103072 · Grafana · Grafana

·

CVE-2026-13719

·

Published

2026-09-30

·

Updated

2026-09-30

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Grafana versions prior to 13.1.0
Description An authenticated user can list alert rules stored in folders they are not allowed to read via the alert rules API list endpoint. If the set of folders the user is permitted to read is empty, the folder restriction is bypassed, resulting in the return of every alert rule within the organization. The exposed information consists of rule configurations, while data source credentials remain protected.
Recommendations Update to version 13.1.0 or later.

Fix

Information Disclosure

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13719

Affected Products

Grafana