Issued at: 2026-09-16
Updated at: 2026-09-17
Advisory content derived from Red Hat RHSA-2026:54243, © Red Hat, Inc., used under CC BY 4.0, with modifications.
Synopsis
Important: grafana security update
Description
Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB.
Security Fix(es):
* grafana: Grafana: Privilege escalation via dashboard overwrite (CVE-2026-33377)
* grafana: Grafana: Denial of Service due to excessive memory allocation via large JSON payloads (CVE-2026-42127)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.