PT-2026-49078 · Grafana · Grafana Operator

·

CVE-2026-11769

·

Published

2026-06-13

·

Updated

2026-07-30

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Grafana Operator versions prior to 5.24.0
Description A path traversal and privilege escalation issue exists when loading dashboards and library panels using the jsonnet data templating language. Because the jsonnet expression is evaluated within the context of the operator manager pod, a malicious user with permissions to create Dashboard or LibraryPanel resources can obtain the Kubernetes service account token of the Grafana Operator manager.
Recommendations Upgrade to version 5.24.0. As a temporary workaround, implement a ValidatingAdmissionPolicy to prevent the creation or modification of jsonnet based resources by denying operations on grafanadashboards and grafanalibrarypanels where the jsonnetLib field is present.

Exploit

Fix

LPE

Path traversal

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11769
GHSA-FCW4-WWQM-M8CF
GHSA-V82C-5C2Q-HX9G
GO-2026-5355
OPENSUSE-SU-2026:21483-1

Affected Products

Grafana Operator