CVE-2026-42129: Grafana Loki Datasource
High severity, CVSS 7.7. EPSS: 0.4% chance of exploitation in the next 30 days.
A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.
Affected products
- Grafana Loki Datasource: affected versions not specified
Published 2026-06-22. Last modified 2026-07-10.