Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-63087: Grafana OnCall 1.16.11 Unauthenticated Access via Plugin Install
CVE-2026-63087
CVE-2026-63087
Summary
An attacker can access Grafana OnCall without a password by sending a specific request to the plugin install endpoint. This allows them to create new users, revoke legitimate access, and redirect API calls to a malicious host. Update Grafana OnCall to version 1.16.12 or later to fix this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| grafana-cold-storage | oncall | <= 1.16.11 |
Original title
Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the internal plugin insta...
Original description
Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the internal plugin install endpoint using hardcoded default stack_id and org_id values present in the public source tree. Attackers can leverage the acquired token to authenticate against all internal API endpoints, create arbitrary Admin users via the user-context header bootstrap path, revoke the legitimate plugin token, and redirect OnCall-to-Grafana API calls to an attacker-controlled host by overwriting the organization's grafana_url and api_token.
mitre CVSS3.1
9.8
Vulnerability type
CWE-306
Missing Authentication for Critical Function
- https://github.com/geo-chen/oss/blob/main/oncall.md technical-description exploit
- https://www.vulncheck.com/advisories/grafana-oncall-unauthenticated-token-hijack... third-party-advisory
Published: 16 Jul 2026 · Updated: 17 Jul 2026 · First seen: 16 Jul 2026