Impact
A flaw in Grafana permits an authenticated user with permission to create or edit alert rules to mark a query as a server-side expression while referencing a legitimate datasource UID. During evaluation, Grafana bypasses the normal datasource query authorization checks, enabling the user to read data through the datasource credentials they do not normally have permission to access. This can lead to the disclosure of sensitive information such as PII, configuration secrets, or business data.
Affected Systems
The vulnerability is present in Grafana Enterprise and Grafana OSS. No specific product versions are listed, so any deployment that includes alert‑rule creation or editing functionality may be affected. Users should verify whether their Grafana instance includes the alert rule feature and consult the vendor or their documentation for an update.
Risk and Exploitability
The CVSS score of 7.1 signals a high severity level, and the absence of an EPSS score or KEV listing does not lower its risk profile. Exploitation requires an authenticated session with the privilege to modify alert rules, which is typically granted to administrative or privileged user accounts. Once the attack is carried out, the attacker can read any data that the datasource credentials allow, potentially exposing confidential information. No publicly available exploits are known, but the nature of the vulnerability permits a targeted attack within an organization.
OpenCVE Enrichment