CVE-2026-42129
Grafana Grafana OSS, loki datasource
A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.
- CVSS
- 7.7
- EPSS
- 0.44% 36.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.22