Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-63087: Grafana OnCall 1.16.11 Unauthenticated Access via Plugin Install

CVE-2026-63087 CVE-2026-63087
Summary

An attacker can access Grafana OnCall without a password by sending a specific request to the plugin install endpoint. This allows them to create new users, revoke legitimate access, and redirect API calls to a malicious host. Update Grafana OnCall to version 1.16.12 or later to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
grafana-cold-storage oncall <= 1.16.11
Original title
Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the internal plugin insta...
Original description
Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the internal plugin install endpoint using hardcoded default stack_id and org_id values present in the public source tree. Attackers can leverage the acquired token to authenticate against all internal API endpoints, create arbitrary Admin users via the user-context header bootstrap path, revoke the legitimate plugin token, and redirect OnCall-to-Grafana API calls to an attacker-controlled host by overwriting the organization's grafana_url and api_token.
mitre CVSS3.1 9.8
Vulnerability type
CWE-306 Missing Authentication for Critical Function
Published: 16 Jul 2026 · Updated: 17 Jul 2026 · First seen: 16 Jul 2026