CVE-2026-15815: CWE-59 in Grafana Grafana OSS
Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, writing arbitrary files and an executable backend binary outside that directory. The dropped executable runs with the privileges of the Grafana server process, resulting in remote code execution. Plugin archives are extracted before their signature is verified, so a valid plugin signature does not prevent the write. An operator can therefore be affected by installing a plugin that appears legitimate, as well as by installing a plugin from an arbitrary archive using grafana-cli, the GF_INSTALL_PLUGINS environment variable, or preinstall configuration. Grafana Enterprise is affected because it includes the same plugin extraction code as Grafana OSS.
AI Analysis
Technical Summary
CVE-2026-15815 is a vulnerability in Grafana OSS and Enterprise where symbolic links in plugin archives are not safely resolved during extraction. An attacker can craft a plugin archive that uses chained relative symbolic links to escape the plugin installation directory and write arbitrary files, including executable binaries, outside the directory. These binaries execute with the privileges of the Grafana server process, resulting in remote code execution. The extraction occurs before plugin signature verification, so even plugins with valid signatures can be exploited. This affects multiple versions of Grafana OSS and Enterprise as explicitly listed.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary code remotely with the privileges of the Grafana server process. This can lead to full system compromise depending on the server's privileges. The vulnerability bypasses plugin signature verification due to extraction order, increasing the risk of installing seemingly legitimate plugins that are malicious.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, avoid installing plugins from untrusted sources or arbitrary archives. Monitor vendor communications for patches or updates addressing this vulnerability.
CVE-2026-15815: CWE-59 in Grafana Grafana OSS
Description
Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, writing arbitrary files and an executable backend binary outside that directory. The dropped executable runs with the privileges of the Grafana server process, resulting in remote code execution. Plugin archives are extracted before their signature is verified, so a valid plugin signature does not prevent the write. An operator can therefore be affected by installing a plugin that appears legitimate, as well as by installing a plugin from an arbitrary archive using grafana-cli, the GF_INSTALL_PLUGINS environment variable, or preinstall configuration. Grafana Enterprise is affected because it includes the same plugin extraction code as Grafana OSS.
CVSS v3.1
Score 8.8high
Affected software
Grafana
Grafana OSS
Grafana
Grafana Enterprise
pkg:github/grafana/grafanaRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-15815 is a vulnerability in Grafana OSS and Enterprise where symbolic links in plugin archives are not safely resolved during extraction. An attacker can craft a plugin archive that uses chained relative symbolic links to escape the plugin installation directory and write arbitrary files, including executable binaries, outside the directory. These binaries execute with the privileges of the Grafana server process, resulting in remote code execution. The extraction occurs before plugin signature verification, so even plugins with valid signatures can be exploited. This affects multiple versions of Grafana OSS and Enterprise as explicitly listed.
Potential Impact
Successful exploitation allows an attacker to execute arbitrary code remotely with the privileges of the Grafana server process. This can lead to full system compromise depending on the server's privileges. The vulnerability bypasses plugin signature verification due to extraction order, increasing the risk of installing seemingly legitimate plugins that are malicious.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, avoid installing plugins from untrusted sources or arbitrary archives. Monitor vendor communications for patches or updates addressing this vulnerability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GRAFANA
- Date Reserved
- 2026-07-15T11:15:50.200Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aac58d955bf5e2cf5ef74bf
Added to database: 09/17/2026, 21:17:13 UTC
Last enriched: 09/17/2026, 21:31:27 UTC
Last updated: 09/18/2026, 01:44:53 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.