Grafana Tempo/Loki Plugins: Unsanitized URL Path Traversal Exposes Admin Credentials
CVE-2026-10601 Published on June 22, 2026
Path traversal in the Tempo and Loki data source plugins
A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative actions on the configured backend.
Weakness Type
What is a Directory traversal Vulnerability?
The software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVE-2026-10601 has been classified to as a Directory traversal vulnerability or weakness.
Products Associated with CVE-2026-10601
Want to know whenever a new CVE is published for Grafana Labs Grafana? stack.watch will email you.
Affected Versions
Grafana OSS:- Version 11.6.0, <= 11.6.14 is affected.
- Version 12.2.0, <= 12.2.8 is affected.
- Version 12.3.0, <= 12.3.6 is affected.
- Version 12.4.0, <= 12.4.3 is affected.
- Version 13.0.0, <= 13.0.1 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.