CVE Tools

Grafana Enterprise

23 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Grafana Enterprise, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.

Grafana Enterprise CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Grafana Enterprise CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-041
2025-050
2025-061
2025-070
2025-080
2025-090
2025-100
2025-111
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-061
2026-071
2026-083
2026-094

Severity

How the 23 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical29%
  • High836%
  • Medium1150%
  • Low15%

Latest CVEs

The 15 most recently published vulnerabilities affecting Grafana Enterprise.

  1. CVE-2026-15815CVE-2026-15815 CVE Record8.8
  2. CVE-2026-76154CVE-2026-76154 CVE Record7.3
  3. CVE-2026-14199Session takeover via Auth Proxy cache key collision7.1
  4. CVE-2026-12704SAML assertion replay via skipped InResponseTo validation6.8
  5. CVE-2026-19197Broken access control in dashboard snapshots6.3
  6. CVE-2026-17183CVE-2026-17183 CVE Record7.1
  7. CVE-2026-11817CVE-2026-11817 CVE Record—
  8. CVE-2026-28378Cross-Organization Public Dashboard Deletion via Missing Org Isolation3.1
  9. CVE-2026-42127Pre-authentication denial of service in the public dashboard query endpoint7.5
  10. CVE-2025-41115Incorrect privilege assignment10.0
  11. CVE-2025-3454This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauth...5.0
  12. CVE-2025-2703The built-in XY Chart plugin is vulnerable to a DOM XSS vulnerability. A user with Editor permissions is able to modify such a panel in order to make it execute arbitrary JavaScript.6.8
  13. CVE-2024-6322Access control for plugin data sources protected by the ReqActions json field of the plugin.json is bypassed if the user or service account is granted associated access to any other data source, as...5.4
  14. CVE-2023-6152A user changing their email after signing up and verifying it can change it without verification in profile settings. The configuration option "verify_email_enabled" will only validate email only ...5.4
  15. CVE-2023-4399Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, Request security is a deny list that allows admins to configure Grafana in a way so that the instance d...6.6

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store