Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.5

Grafana: Unauthenticated Data Exposure via SQL Injection

RHSA-2026:3880
Summary

Grafana, a popular data visualization tool, has a security issue that allows attackers to access sensitive data without a password. This could happen if an attacker discovers a way to inject malicious SQL code into the system. You should update Grafana to the latest version to protect your data from unauthorized access.

What to do
  • Update redhat grafana to version 0:7.5.11-9.el8_6.
  • Update redhat grafana-debuginfo to version 0:7.5.11-9.el8_6.
Affected software
VendorProductAffected versionsFix available
redhat grafana <= 0:7.5.11-9.el8_6 0:7.5.11-9.el8_6
redhat grafana-debuginfo <= 0:7.5.11-9.el8_6 0:7.5.11-9.el8_6
redhat grafana <= 0:7.5.11-9.el8_6 0:7.5.11-9.el8_6
redhat grafana-debuginfo <= 0:7.5.11-9.el8_6 0:7.5.11-9.el8_6
redhat grafana <= 0:7.5.11-9.el8_6 0:7.5.11-9.el8_6
redhat grafana-debuginfo <= 0:7.5.11-9.el8_6 0:7.5.11-9.el8_6
Original title
Red Hat Security Advisory: grafana security update
osv CVSS3.1 7.5
Published: 6 Mar 2026 · Updated: 7 Mar 2026 · First seen: 6 Mar 2026