CVE-2026-27877 Details
Description
When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as possible to improve your deployments' security.
A vulnerability exists in Grafana that exposes passwords of direct data sources when public dashboards are used, even if those data sources are not actively utilized in the dashboards. This issue does not affect proxied data sources. Users are advised to convert direct data sources to proxied ones whenever possible to enhance security.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:10223 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:10226 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:11416 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:11417 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:19134 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:19352 | redhat-SADP | |
| https://access.redhat.com/security/cve/CVE-2026-27877 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2452293 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27877.json | redhat-SADP | |
| https://grafana.com/security/security-advisories/cve-2026-27877 | CISA-ADP | Vendor Advisory |
| https://grafana.com/security/security-advisories/cve-2026-27877 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-201 | Insertion of Sensitive Information Into Sent Data | redhat-SADP |
| CWE-312 | Cleartext Storage of Sensitive Information | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| grafana grafana | < 9.3.0 >= 11.6.14, < 12.0.0 >= 12.1.10, < 12.2.0 >= 12.2.8, < 12.3.0 >= 12.3.6, < 12.4.0 |
CPE
Remediation
| |
Change History
9 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 10, 2026 | CVE Modified | CISA-ADP |
| Mar 31, 2026 | Initial Analysis | [email protected] |
| Mar 27, 2026 | CVE Modified | CISA-ADP |
| Mar 27, 2026 | New CVE Received | [email protected] |