Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.1

Grafana: Unauthenticated Data Exposure and Remote Code Execution

RHSA-2026:2920
Summary

Grafana, a popular data visualization tool, has a security issue that could allow an attacker to access sensitive data and execute malicious code without needing a login. If left unpatched, this vulnerability could put your organization's data and systems at risk. Apply the latest security updates to ensure you're protected.

What to do
  • Update redhat grafana to version 0:10.2.6-18.el9_7.
  • Update redhat grafana-debuginfo to version 0:10.2.6-18.el9_7.
  • Update redhat grafana-debugsource to version 0:10.2.6-18.el9_7.
  • Update redhat grafana-selinux to version 0:10.2.6-18.el9_7.
Affected software
VendorProductAffected versionsFix available
redhat grafana <= 0:10.2.6-18.el9_7 0:10.2.6-18.el9_7
redhat grafana-debuginfo <= 0:10.2.6-18.el9_7 0:10.2.6-18.el9_7
redhat grafana-debugsource <= 0:10.2.6-18.el9_7 0:10.2.6-18.el9_7
redhat grafana-selinux <= 0:10.2.6-18.el9_7 0:10.2.6-18.el9_7
Original title
Red Hat Security Advisory: grafana security update
osv CVSS3.1 8.1
Published: 19 Feb 2026 · Updated: 7 Mar 2026 · First seen: 6 Mar 2026