Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/grafana/grafana
  4. ›
  5. CVE-2026-27877

CVE-2026-27877: Grafana public dashboards disclose all direct mode datasources

March 27, 2026 (updated May 13, 2026)

When using public dashboards and direct data-sources, all direct data-sources’ passwords are exposed despite not being used in dashboards.

No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as possible to improve your deployments’ security.

References

  • github.com/advisories/GHSA-3q27-7qjq-p9c5
  • grafana.com/security/security-advisories/cve-2026-27877
  • nvd.nist.gov/vuln/detail/CVE-2026-27877

Code Behaviors & Features

Detect and mitigate CVE-2026-27877 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 1.9.2-0.20221116104934-4ee83a5f2bf4 before 1.9.2-0.20260325055210-3522153e07b4, all versions starting from 9.3.0 before 11.6.14, all versions starting from 12.0.0 before 12.1.10, all versions starting from 12.2.0 before 12.2.8, all versions starting from 12.3.0 before 12.3.6, all versions starting from 12.4.0 before 12.4.2

Fixed versions

  • 1.9.2-0.20260325055210-3522153e07b4
  • 11.6.14
  • 12.1.10
  • 12.2.8
  • 12.3.6
  • 12.4.2

Solution

Upgrade to versions 1.9.2-0.20260325055210-3522153e07b4, 11.6.14, 12.1.10, 12.2.8, 12.3.6, 12.4.2 or above.

Impact 6.5 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
  • CWE-312: Cleartext Storage of Sensitive Information

Source file

go/github.com/grafana/grafana/CVE-2026-27877.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Thu, 21 May 2026 12:19:22 +0000.