Grafana Enterprise
23 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Grafana Enterprise, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
Grafana Enterprise CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 1 |
| 2025-05 | 0 |
| 2025-06 | 1 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 1 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 1 |
| 2026-07 | 1 |
| 2026-08 | 3 |
| 2026-09 | 4 |
Severity
How the 23 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High8
- Medium11
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting Grafana Enterprise.
- CVE-2026-15815CVE-2026-15815 CVE Record8.8
- CVE-2026-76154CVE-2026-76154 CVE Record7.3
- CVE-2026-14199Session takeover via Auth Proxy cache key collision7.1
- CVE-2026-12704SAML assertion replay via skipped InResponseTo validation6.8
- CVE-2026-19197Broken access control in dashboard snapshots6.3
- CVE-2026-17183CVE-2026-17183 CVE Record7.1
- CVE-2026-11817CVE-2026-11817 CVE Record—
- CVE-2026-28378Cross-Organization Public Dashboard Deletion via Missing Org Isolation3.1
- CVE-2026-42127Pre-authentication denial of service in the public dashboard query endpoint7.5
- CVE-2025-41115Incorrect privilege assignment10.0
- CVE-2025-3454This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauth...5.0
- CVE-2025-2703The built-in XY Chart plugin is vulnerable to a DOM XSS vulnerability. A user with Editor permissions is able to modify such a panel in order to make it execute arbitrary JavaScript.6.8
- CVE-2024-6322Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is granted associated access to any other data source, as...5.4
- CVE-2023-6152A user changing their email after signing up and verifying it can change it without verification in profile settings. The configuration option "verify_email_enabled" will only validate email only ...5.4
- CVE-2023-4399Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, Request security is a deny list that allows admins to configure Grafana in a way so that the instance d...6.6
Product grouping is registry-driven, with AI assist and human review. How it works