Ce mail provient de l'extérieur, restons vigilants ===================================================================== CERT-Renater Note d'Information No. 2026/VULN912 _____________________________________________________________________ DATE : 17/09/2026 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running Grafana OSS, Grafana Enterprise versions prior to 13.2.2, 13.1.6, 13.0.9, 12.4.11. ===================================================================== https://github.com/grafana/grafana/releases https://github.com/advisories/GHSA-xp8x-3q7w-cpqr https://github.com/advisories/GHSA-35gc-393c-vjxf _____________________________________________________________________ Grafana OSS and Grafana Enterprise did not safely resolve... High severity Unreviewed Published 13 hours ago to the GitHub Advisory Database • Package No package listed— Suggest a package Affected versions Unknown Patched versions Unknown Description Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, writing arbitrary files and an executable backend binary outside that directory. The dropped executable runs with the privileges of the Grafana server process, resulting in remote code execution. Plugin archives are extracted before their signature is verified, so a valid plugin signature does not prevent the write. An operator can therefore be affected by installing a plugin that appears legitimate, as well as by installing a plugin from an arbitrary archive using grafana-cli, the GF_INSTALL_PLUGINS environment variable, or preinstall configuration. Grafana Enterprise is affected because it includes the same plugin extraction code as Grafana OSS. References https://nvd.nist.gov/vuln/detail/CVE-2026-15815 https://grafana.com/security/security-advisories/cve-2026-15815 Severity High 8.8/ 10 CVSS v3 base metrics Attack vector Network Attack complexity Low Privileges required None User interaction Required Scope Unchanged Confidentiality High Integrity High Availability High CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H EPSS score Weaknesses Weakness CWE-22 CVE ID CVE-2026-15815 GHSA ID GHSA-xp8x-3q7w-cpqr _____________________________________________________________________ A stored cross-site scripting vulnerability in the Geomap... High severity Unreviewed Published 13 hours ago to the GitHub Advisory Database • Package No package listed— Suggest a package Affected versions Unknown Patched versions Unknown Description A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user's session by hosting a malicious style configuration, enabling escalation to Org Admin. References https://nvd.nist.gov/vuln/detail/CVE-2026-76154 https://grafana.com/security/security-advisories/cve-2026-76154 Severity High 7.3/ 10 CVSS v3 base metrics Attack vector Network Attack complexity Low Privileges required Low User interaction Required Scope Unchanged Confidentiality High Integrity High Availability None CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N EPSS score Weaknesses Weakness CWE-79 CVE ID CVE-2026-76154 GHSA ID GHSA-35gc-393c-vjxf ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================