Description
An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a server-side expression while referencing a real datasource UID (incorrect authorization). This can expose data accessible through Grafana's configured datasource credentials to users who lack permission to query that datasource.
Published: 2026-08-19
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Grafana permits an authenticated user with permission to create or edit alert rules to mark a query as a server-side expression while referencing a legitimate datasource UID. During evaluation, Grafana bypasses the normal datasource query authorization checks, enabling the user to read data through the datasource credentials they do not normally have permission to access. This can lead to the disclosure of sensitive information such as PII, configuration secrets, or business data.

Affected Systems

The vulnerability is present in Grafana Enterprise and Grafana OSS. No specific product versions are listed, so any deployment that includes alert‑rule creation or editing functionality may be affected. Users should verify whether their Grafana instance includes the alert rule feature and consult the vendor or their documentation for an update.

Risk and Exploitability

The CVSS score of 7.1 signals a high severity level, and the absence of an EPSS score or KEV listing does not lower its risk profile. Exploitation requires an authenticated session with the privilege to modify alert rules, which is typically granted to administrative or privileged user accounts. Once the attack is carried out, the attacker can read any data that the datasource credentials allow, potentially exposing confidential information. No publicly available exploits are known, but the nature of the vulnerability permits a targeted attack within an organization.

Generated by OpenCVE AI on August 20, 2026 at 12:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Grafana to the latest released version that includes the fix for CVE-2026-17183
  • Restrict the ability to create or edit alert rules to only trusted administrators or privileged accounts
  • Monitor alert rule changes for suspicious activity and review datasource query logs for unauthorized access patterns

Generated by OpenCVE AI on August 20, 2026 at 12:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Grafana
Grafana grafana
Vendors & Products Grafana
Grafana grafana

Wed, 19 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description Summary An authenticated organization user who can create or edit alert rules in a folder can query a datasource for which they do not have datasources:query permission. The attacker sets the client-controlled query field queryType to __expr__ while retaining the UID of a real datasource. The alert-rule authorization path treats the query as a server-side expression and skips datasource permission enforcement, while the evaluator subsequently resolves and executes the query against the real datasource identified by datasourceUid. ## Impact This bypass can expose data accessible through Grafana's configured datasource credentials to a low-privileged user who is not authorized to query that datasource directly. Confidentiality impact is High. Integrity impact is Low because some datasource backends and configured credentials may permit state-changing queries. No availability impact has been demonstrated. ## Attack prerequisites - Authenticated, low-privileged user in the same Grafana organization - Permission to create or edit alert rules in an accessible folder - No datasources:query permission for the targeted datasource - Knowledge or discovery of the targeted datasource UID - No user interaction required ## Technical details / root cause 1. The attacker submits an alert-rule query with queryType: "__expr__" and the UID of a real datasource. 2. The datasource authorization helper skips permission enforcement when query.QueryType == "__expr__". 3. queryType is client-controlled and is not validated against the referenced datasource. 4. During evaluation, Grafana selects and loads the actual datasource using DatasourceUID, not the spoofed queryType. 5. The query therefore executes using Grafana's datasource credentials despite the caller lacking datasources:query. The root cause is inconsistent query classification between authorization and execution: authorization trusts queryType, while execution trusts DatasourceUID. ## Affected product / component - Product: Grafana OSS - Component: Unified Alerting / ngalert - Area: Alert-rule datasource authorization and query evaluation - Confirmed version: Grafana OSS 13.0.1 - Affected version range: not yet assessed CVSS Scope is Unchanged because the vulnerable authorization decision and resulting impact remain within Grafana's security authority. ## Source - Researcher: czarflix ## Related report / duplicate assessment This is a default-Grafana-OSS reproduction of the root cause previously reported in GRAFANALABS-IAQAFIXI. The earlier submission was archived as Not Applicable because its proof of concept depended on Cloud/Enterprise-specific permission mechanisms, and the researcher was invited to demonstrate the issue under default OSS permissions. This report establishes that missing prerequisite and should be treated as the actionable OSS submission, not dismissed as a duplicate. VUL-2026-0095 and VUL-2026-0126 concern Enterprise Recorded Queries and have different components, endpoints, and root causes; they are related authorization issues but not duplicates. ## Recommended remediation - Do not exempt a query from datasource authorization based solely on client-controlled queryType. - Resolve the referenced datasource server-side before authorization and apply datasources:query whenever the resolved UID represents a real datasource. - Require expression queries to reference only the canonical server-side expression datasource and reject mismatches such as queryType: "__expr__" paired with a real datasource UID. - Ensure authorization and evaluation use the same canonical datasource identity and fail closed when fields conflict. - Add regression coverage for an OSS user with folder-level alert-rule edit permission but without datasource query permission, including mismatched queryType and datasourceUid values. An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a server-side expression while referencing a real datasource UID (incorrect authorization). This can expose data accessible through Grafana's configured datasource credentials to users who lack permission to query that datasource.
References

Wed, 19 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Description Summary An authenticated organization user who can create or edit alert rules in a folder can query a datasource for which they do not have datasources:query permission. The attacker sets the client-controlled query field queryType to __expr__ while retaining the UID of a real datasource. The alert-rule authorization path treats the query as a server-side expression and skips datasource permission enforcement, while the evaluator subsequently resolves and executes the query against the real datasource identified by datasourceUid. ## Impact This bypass can expose data accessible through Grafana's configured datasource credentials to a low-privileged user who is not authorized to query that datasource directly. Confidentiality impact is High. Integrity impact is Low because some datasource backends and configured credentials may permit state-changing queries. No availability impact has been demonstrated. ## Attack prerequisites - Authenticated, low-privileged user in the same Grafana organization - Permission to create or edit alert rules in an accessible folder - No datasources:query permission for the targeted datasource - Knowledge or discovery of the targeted datasource UID - No user interaction required ## Technical details / root cause 1. The attacker submits an alert-rule query with queryType: "__expr__" and the UID of a real datasource. 2. The datasource authorization helper skips permission enforcement when query.QueryType == "__expr__". 3. queryType is client-controlled and is not validated against the referenced datasource. 4. During evaluation, Grafana selects and loads the actual datasource using DatasourceUID, not the spoofed queryType. 5. The query therefore executes using Grafana's datasource credentials despite the caller lacking datasources:query. The root cause is inconsistent query classification between authorization and execution: authorization trusts queryType, while execution trusts DatasourceUID. ## Affected product / component - Product: Grafana OSS - Component: Unified Alerting / ngalert - Area: Alert-rule datasource authorization and query evaluation - Confirmed version: Grafana OSS 13.0.1 - Affected version range: not yet assessed ## Severity - CVSS 3.1: 7.1 High - Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N - CWE-863: Incorrect Authorization Scope is Unchanged because the vulnerable authorization decision and resulting impact remain within Grafana's security authority. ## Source - Researcher: czarflix - Intigriti report: GRAFANALABS-F996ATD7 - Report URL: https://app.intigriti.com/company/submissions/GRAFANALABS-F996ATD7 ## Related report / duplicate assessment This is a default-Grafana-OSS reproduction of the root cause previously reported in GRAFANALABS-IAQAFIXI. The earlier submission was archived as Not Applicable because its proof of concept depended on Cloud/Enterprise-specific permission mechanisms, and the researcher was invited to demonstrate the issue under default OSS permissions. This report establishes that missing prerequisite and should be treated as the actionable OSS submission, not dismissed as a duplicate. VUL-2026-0095 and VUL-2026-0126 concern Enterprise Recorded Queries and have different components, endpoints, and root causes; they are related authorization issues but not duplicates. ## Recommended remediation - Do not exempt a query from datasource authorization based solely on client-controlled queryType. - Resolve the referenced datasource server-side before authorization and apply datasources:query whenever the resolved UID represents a real datasource. - Require expression queries to reference only the canonical server-side expression datasource and reject mismatches such as queryType: "__expr__" paired with a real datasource UID. - Ensure authorization and evaluation use the same canonical datasource identity and fail closed when fields conflict. - Add regression coverage for an OSS user with folder-level alert-rule edit permission but without datasource query permission, including mismatched queryType and datasourceUid values. Summary An authenticated organization user who can create or edit alert rules in a folder can query a datasource for which they do not have datasources:query permission. The attacker sets the client-controlled query field queryType to __expr__ while retaining the UID of a real datasource. The alert-rule authorization path treats the query as a server-side expression and skips datasource permission enforcement, while the evaluator subsequently resolves and executes the query against the real datasource identified by datasourceUid. ## Impact This bypass can expose data accessible through Grafana's configured datasource credentials to a low-privileged user who is not authorized to query that datasource directly. Confidentiality impact is High. Integrity impact is Low because some datasource backends and configured credentials may permit state-changing queries. No availability impact has been demonstrated. ## Attack prerequisites - Authenticated, low-privileged user in the same Grafana organization - Permission to create or edit alert rules in an accessible folder - No datasources:query permission for the targeted datasource - Knowledge or discovery of the targeted datasource UID - No user interaction required ## Technical details / root cause 1. The attacker submits an alert-rule query with queryType: "__expr__" and the UID of a real datasource. 2. The datasource authorization helper skips permission enforcement when query.QueryType == "__expr__". 3. queryType is client-controlled and is not validated against the referenced datasource. 4. During evaluation, Grafana selects and loads the actual datasource using DatasourceUID, not the spoofed queryType. 5. The query therefore executes using Grafana's datasource credentials despite the caller lacking datasources:query. The root cause is inconsistent query classification between authorization and execution: authorization trusts queryType, while execution trusts DatasourceUID. ## Affected product / component - Product: Grafana OSS - Component: Unified Alerting / ngalert - Area: Alert-rule datasource authorization and query evaluation - Confirmed version: Grafana OSS 13.0.1 - Affected version range: not yet assessed CVSS Scope is Unchanged because the vulnerable authorization decision and resulting impact remain within Grafana's security authority. ## Source - Researcher: czarflix ## Related report / duplicate assessment This is a default-Grafana-OSS reproduction of the root cause previously reported in GRAFANALABS-IAQAFIXI. The earlier submission was archived as Not Applicable because its proof of concept depended on Cloud/Enterprise-specific permission mechanisms, and the researcher was invited to demonstrate the issue under default OSS permissions. This report establishes that missing prerequisite and should be treated as the actionable OSS submission, not dismissed as a duplicate. VUL-2026-0095 and VUL-2026-0126 concern Enterprise Recorded Queries and have different components, endpoints, and root causes; they are related authorization issues but not duplicates. ## Recommended remediation - Do not exempt a query from datasource authorization based solely on client-controlled queryType. - Resolve the referenced datasource server-side before authorization and apply datasources:query whenever the resolved UID represents a real datasource. - Require expression queries to reference only the canonical server-side expression datasource and reject mismatches such as queryType: "__expr__" paired with a real datasource UID. - Ensure authorization and evaluation use the same canonical datasource identity and fail closed when fields conflict. - Add regression coverage for an OSS user with folder-level alert-rule edit permission but without datasource query permission, including mismatched queryType and datasourceUid values.
References

Wed, 19 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Description Summary An authenticated organization user who can create or edit alert rules in a folder can query a datasource for which they do not have datasources:query permission. The attacker sets the client-controlled query field queryType to __expr__ while retaining the UID of a real datasource. The alert-rule authorization path treats the query as a server-side expression and skips datasource permission enforcement, while the evaluator subsequently resolves and executes the query against the real datasource identified by datasourceUid. ## Impact This bypass can expose data accessible through Grafana's configured datasource credentials to a low-privileged user who is not authorized to query that datasource directly. Confidentiality impact is High. Integrity impact is Low because some datasource backends and configured credentials may permit state-changing queries. No availability impact has been demonstrated. ## Attack prerequisites - Authenticated, low-privileged user in the same Grafana organization - Permission to create or edit alert rules in an accessible folder - No datasources:query permission for the targeted datasource - Knowledge or discovery of the targeted datasource UID - No user interaction required ## Technical details / root cause 1. The attacker submits an alert-rule query with queryType: "__expr__" and the UID of a real datasource. 2. The datasource authorization helper skips permission enforcement when query.QueryType == "__expr__". 3. queryType is client-controlled and is not validated against the referenced datasource. 4. During evaluation, Grafana selects and loads the actual datasource using DatasourceUID, not the spoofed queryType. 5. The query therefore executes using Grafana's datasource credentials despite the caller lacking datasources:query. The root cause is inconsistent query classification between authorization and execution: authorization trusts queryType, while execution trusts DatasourceUID. ## Affected product / component - Product: Grafana OSS - Component: Unified Alerting / ngalert - Area: Alert-rule datasource authorization and query evaluation - Confirmed version: Grafana OSS 13.0.1 - Affected version range: not yet assessed ## Severity - CVSS 3.1: 7.1 High - Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N - CWE-863: Incorrect Authorization Scope is Unchanged because the vulnerable authorization decision and resulting impact remain within Grafana's security authority. ## Source - Researcher: czarflix - Intigriti report: GRAFANALABS-F996ATD7 - Report URL: https://app.intigriti.com/company/submissions/GRAFANALABS-F996ATD7 ## Related report / duplicate assessment This is a default-Grafana-OSS reproduction of the root cause previously reported in GRAFANALABS-IAQAFIXI. The earlier submission was archived as Not Applicable because its proof of concept depended on Cloud/Enterprise-specific permission mechanisms, and the researcher was invited to demonstrate the issue under default OSS permissions. This report establishes that missing prerequisite and should be treated as the actionable OSS submission, not dismissed as a duplicate. VUL-2026-0095 and VUL-2026-0126 concern Enterprise Recorded Queries and have different components, endpoints, and root causes; they are related authorization issues but not duplicates. ## Recommended remediation - Do not exempt a query from datasource authorization based solely on client-controlled queryType. - Resolve the referenced datasource server-side before authorization and apply datasources:query whenever the resolved UID represents a real datasource. - Require expression queries to reference only the canonical server-side expression datasource and reject mismatches such as queryType: "__expr__" paired with a real datasource UID. - Ensure authorization and evaluation use the same canonical datasource identity and fail closed when fields conflict. - Add regression coverage for an OSS user with folder-level alert-rule edit permission but without datasource query permission, including mismatched queryType and datasourceUid values.
Title CVE-2026-17183 CVE Record
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GRAFANA

Published:

Updated: 2026-08-27T17:22:31.524Z

Reserved: 2026-07-24T18:38:02.221Z

Link: CVE-2026-17183

cve-icon Vulnrichment

Updated: 2026-08-19T18:42:00.562Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T18:16:35.940

Modified: 2026-08-31T18:50:00.053

Link: CVE-2026-17183

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T20:45:03Z

Weaknesses