PT-2026-51299 · Grafana+1 · Loki Datasource Plugin+3

·

CVE-2026-10601

·

Published

2026-06-22

·

Updated

2026-07-14

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Tempo datasource plugin (affected versions not specified) Loki datasource plugin (affected versions not specified)
Description These plugins construct backend HTTP requests by interpolating user-supplied input into URL paths without sanitization, which allows for path traversal. A user with a Viewer role can capture admin-configured datasource credentials, specifically secureJsonData custom headers, by traversing to an attacker-controlled endpoint. Additionally, this allows for the invocation of state-changing admin endpoints on Tempo, such as '/flush' and '/shutdown', and the exfiltration of internal service data through Loki's CallResource, which returns full HTTP response bodies.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10549
BIT-GRAFANA-2026-10601
CVE-2026-10601

Affected Products

Grafana
Loki Datasource Plugin
Red Os
Tempo Datasource Plugin