CVE-2026-42129

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
22/06/2026
Last modified:
10/07/2026

Description

A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:grafana:loki_datasource:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools