CVE-2026-42129: Grafana Loki Datasource

High severity, CVSS 7.7. EPSS: 0.4% chance of exploitation in the next 30 days.

A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.

Affected products

  • Grafana Loki Datasource: affected versions not specified

Published 2026-06-22. Last modified 2026-07-10.