Куда я попал?
SECURITM это SGRC система, ? автоматизирующая процессы в службах информационной безопасности. SECURITM помогает построить и управлять ИСПДн, КИИ, ГИС, СМИБ/СУИБ, банковскими системами защиты.
А еще SECURITM это место для обмена опытом и наработками для служб безопасности.

CVE-2026-15815

PUBLISHED 17.09.2026

CNA: GRAFANA

CVE-2026-15815 CVE Record

Обновлено: 17.09.2026
Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, writing arbitrary files and an executable backend binary outside that directory. The dropped executable runs with the privileges of the Grafana server process, resulting in remote code execution. Plugin archives are extracted before their signature is verified, so a valid plugin signature does not prevent the write. An operator can therefore be affected by installing a plugin that appears legitimate, as well as by installing a plugin from an arbitrary archive using grafana-cli, the GF_INSTALL_PLUGINS environment variable, or preinstall configuration. Grafana Enterprise is affected because it includes the same plugin extraction code as Grafana OSS.

CWE

Идентификатор Описание
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CWE-59 The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

CVSS

Оценка Severity Версия Базовый вектор
8.8 HIGH 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Доп. Информация

Product Status

Grafana OSS
Product: Grafana OSS
Vendor: Grafana
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось до версии 11.6.17 affected
Наблюдалось в версии 12.0.0 affected
Наблюдалось в версии 12.1.0 affected
Наблюдалось в версии 12.2.0 affected
Наблюдалось в версии 12.3.0 affected
Наблюдалось до версии 12.4.10 affected
Наблюдалось до версии 13.0.8 affected
Наблюдалось до версии 13.1.5 affected
Наблюдалось до версии 13.2.1 affected
Grafana Enterprise
Product: Grafana Enterprise
Vendor: Grafana
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось до версии 11.6.17 affected
Наблюдалось в версии 12.0.0 affected
Наблюдалось в версии 12.1.0 affected
Наблюдалось в версии 12.2.0 affected
Наблюдалось в версии 12.3.0 affected
Наблюдалось до версии 12.4.10 affected
Наблюдалось до версии 13.0.8 affected
Наблюдалось до версии 13.1.5 affected
Наблюдалось до версии 13.2.1 affected
 

Ссылки

Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.