Skip to main content

CVE-2026-15815: CWE-59 in Grafana Grafana OSS

0
High
Published: 09/17/2026 (09/17/2026, 21:31:42 UTC)
Source: CVE Database V5
Vendor/Project: Grafana
Product: Grafana OSS

Description

Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, writing arbitrary files and an executable backend binary outside that directory. The dropped executable runs with the privileges of the Grafana server process, resulting in remote code execution. Plugin archives are extracted before their signature is verified, so a valid plugin signature does not prevent the write. An operator can therefore be affected by installing a plugin that appears legitimate, as well as by installing a plugin from an arbitrary archive using grafana-cli, the GF_INSTALL_PLUGINS environment variable, or preinstall configuration. Grafana Enterprise is affected because it includes the same plugin extraction code as Grafana OSS.

CVSS v3.1

Score 8.8high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected software

Grafana

Grafana OSS

Affected versions
>=11.6.0 <=11.6.17>=12.4.0 <=12.4.10>=13.0.0 <=13.0.8>=13.1.0 <=13.1.5>=13.2.0 <=13.2.1=12.0.0=12.1.0=12.2.0=12.3.0

Grafana

Grafana Enterprise

Affected versions
>=11.6.0 <=11.6.17>=12.4.0 <=12.4.10>=13.0.0 <=13.0.8>=13.1.0 <=13.1.5>=13.2.0 <=13.2.1=12.0.0=12.1.0=12.2.0=12.3.0
GitHub Actionsmore threats →ai
grafana/grafana
pkg:github/grafana/grafana
Affected versions
>=11.6.0 <=11.6.17>=12.4.0 <=12.4.10>=13.0.0 <=13.0.8>=13.1.0 <=13.1.5>=13.2.0 <=13.2.1=12.0.0=12.1.0=12.2.0=12.3.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/17/2026, 21:31:27 UTC

Technical Analysis

CVE-2026-15815 is a vulnerability in Grafana OSS and Enterprise where symbolic links in plugin archives are not safely resolved during extraction. An attacker can craft a plugin archive that uses chained relative symbolic links to escape the plugin installation directory and write arbitrary files, including executable binaries, outside the directory. These binaries execute with the privileges of the Grafana server process, resulting in remote code execution. The extraction occurs before plugin signature verification, so even plugins with valid signatures can be exploited. This affects multiple versions of Grafana OSS and Enterprise as explicitly listed.

Potential Impact

Successful exploitation allows an attacker to execute arbitrary code remotely with the privileges of the Grafana server process. This can lead to full system compromise depending on the server's privileges. The vulnerability bypasses plugin signature verification due to extraction order, increasing the risk of installing seemingly legitimate plugins that are malicious.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, avoid installing plugins from untrusted sources or arbitrary archives. Monitor vendor communications for patches or updates addressing this vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GRAFANA
Date Reserved
2026-07-15T11:15:50.200Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6aac58d955bf5e2cf5ef74bf

Added to database: 09/17/2026, 21:17:13 UTC

Last enriched: 09/17/2026, 21:31:27 UTC

Last updated: 09/18/2026, 01:44:53 UTC

Views: 9

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses