CVE-2026-13719
Received Received - Intake

Authenticated User Access to Unauthorized Alert Rules in Grafana

Vulnerability report for CVE-2026-13719, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Grafana Labs

Description

An authenticated user can list alert rules stored in folders they are not allowed to read through the alert rules API list endpoint. When the set of folders the user may read was empty, the folder restriction was dropped and every alert rule in the organization was returned. From Grafana 13.1.0, any user can trigger this with a folder filter. The exposed data is rule configuration; data source credentials are not exposed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 11 associated CPEs
Vendor Product Version / Range
grafana grafana 13.1.0
grafana grafana to 12.3.0 (inc)
grafana grafana to 12.4.12 (inc)
grafana grafana to 13.0.10 (inc)
grafana grafana to 13.1.7 (inc)
grafana grafana to 13.2.3 (inc)
grafana grafana to 12.3.0 (exc)
grafana grafana From 12.4.0 (inc) to 12.4.12 (exc)
grafana grafana From 13.0.0 (inc) to 13.0.10 (exc)
grafana grafana From 13.1.0 (inc) to 13.1.7 (exc)
grafana grafana From 13.2.0 (inc) to 13.2.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an authenticated user to list alert rules in folders they are not permitted to access through the alert rules API. When a user has no readable folders, the restriction is removed, granting access to all alert rules in the organization. Starting from Grafana 13.1.0, any user can exploit this by applying a folder filter.

Detection Guidance

To detect this vulnerability, check Grafana logs for unauthorized access attempts to the alert rules API list endpoint. Look for requests with folder filters that return more rules than expected. Verify user permissions and folder access restrictions in Grafana's configuration.

Impact Analysis

An attacker could gain unauthorized access to sensitive alert rule configurations, potentially exposing internal monitoring setups or business logic. However, data source credentials are not exposed, limiting the immediate impact.

Compliance Impact

This vulnerability allows unauthorized access to alert rule configurations, which may include sensitive metadata about monitoring setups. While it does not expose data source credentials, the exposed rule configurations could potentially reveal information about data collection practices. This may impact compliance by violating principles of data minimization and access control required by standards like GDPR and HIPAA, depending on the nature of the alert rules and the data they reference.

Mitigation Strategies

Upgrade Grafana to a fixed version (12.3.0, 12.4.12, 13.0.10, 13.1.7, or 13.2.3). Review and restrict user permissions to ensure only authorized users can access alert rules. Monitor API access logs for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13719. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart