Description
Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when
extracting plugin archives. A crafted plugin archive can chain relative symbolic link
entries to escape the plugin installation directory, writing arbitrary files and an
executable backend binary outside that directory. The dropped executable runs with the
privileges of the Grafana server process, resulting in remote code execution.

Plugin archives are extracted before their signature is verified, so a valid plugin
signature does not prevent the write. An operator can therefore be affected by
installing a plugin that appears legitimate, as well as by installing a plugin from an
arbitrary archive using grafana-cli, the GF_INSTALL_PLUGINS environment variable, or
preinstall configuration.

Grafana Enterprise is affected because it includes the same plugin extraction code as
Grafana OSS.
Published: 2026-09-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability appears when Grafana extracts plugin archives without properly resolving symbolic links. A malicious archive can chain relative symbolic link entries so that files are written outside the intended plugin directory, allowing the attacker to drop an executable backend binary that runs with Grafana's process privileges. This leads to full remote code execution on the host. The weakness maps to path traversal (CWE-22), symbolic link attacks (CWE-59) and code injection through arbitrary file write (CWE-94).

Affected Systems

Affected systems include Grafana OSS and Grafana Enterprise deployments. No specific version range is listed, so all current installations that include the described extraction code are potentially vulnerable. Operators of any Grafana instance that permits plugin installation should assume the risk.

Risk and Exploitability

The CVSS score of 8.8 marks the flaw as high severity, and the EPSS score of less than 1% indicates that exploit attempts are currently rare, but the impact is catastrophic. The vulnerability is not yet listed in the CISA KEV catalog, yet any Grafana instance that accepts third‑party plugins—whether through the UI, grafana-cli, the GF_INSTALL_PLUGINS environment variable or pre‑install configuration—could be compromised. The attack vector is therefore limited to the plugin installation process, but once a plugin is installed the compromise is immediate and unrestricted.

Generated by OpenCVE AI on September 18, 2026 at 23:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest Grafana release that contains the plugin extraction fix.
  • Disable automatic plugin installation or restrict GF_INSTALL_PLUGINS to a whitelisted set of trusted plugins.
  • Review and remove any existing plugins that were installed from untrusted sources, and manually verify that no unexpected files exist outside the plugin directories.
  • If an upgrade cannot be performed immediately, overwrite the plugin extraction routine with a patched script that resolves symbolic links securely or add file system permissions to restrict write access to the plugin directory.

Generated by OpenCVE AI on September 18, 2026 at 23:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Sat, 19 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Grafana
Grafana grafana
Grafana grafana Enterprise
Vendors & Products Grafana
Grafana grafana
Grafana grafana Enterprise

Thu, 17 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, writing arbitrary files and an executable backend binary outside that directory. The dropped executable runs with the privileges of the Grafana server process, resulting in remote code execution. Plugin archives are extracted before their signature is verified, so a valid plugin signature does not prevent the write. An operator can therefore be affected by installing a plugin that appears legitimate, as well as by installing a plugin from an arbitrary archive using grafana-cli, the GF_INSTALL_PLUGINS environment variable, or preinstall configuration. Grafana Enterprise is affected because it includes the same plugin extraction code as Grafana OSS.
Title CVE-2026-15815 CVE Record
Weaknesses CWE-22
CWE-59
CWE-94
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Grafana Grafana Grafana Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: GRAFANA

Published:

Updated: 2026-09-19T03:56:26.777Z

Reserved: 2026-07-15T11:15:50.200Z

Link: CVE-2026-15815

cve-icon Vulnrichment

Updated: 2026-09-18T14:29:25.351Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T21:17:11.210

Modified: 2026-09-19T04:17:53.427

Link: CVE-2026-15815

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-30T12:39:01Z

Links: CVE-2026-15815 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T23:45:15Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')