CVE-2024-1442: Grafana

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user access to read, query, edit and delete all data sources within the organization.

Affected products

  • Grafana Grafana: from 8.5.0, before 9.5.7 (fixed in 9.5.7); from 10.0.0, before 10.0.12 (fixed in 10.0.12); from 10.1.0, before 10.1.8 (fixed in 10.1.8); from 10.2.0, before 10.2.5 (fixed in 10.2.5); from 10.3.0, before 10.3.4 (fixed in 10.3.4)

Published 2024-03-07. Last modified 2026-06-17.