Sceawere
Vulnerability Detail
CVE-2026-13719UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Grafana Unauthorized Alert Rule Disclosure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 2h ago
- Vendor
- Grafana
- Product
- Grafana Enterprise
- Attack Type
- CWE-863
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
An authenticated user can list alert rules stored in folders they are not allowed to read through the alert rules API list endpoint. When the set of folders the user may read was empty, the folder restriction was dropped and every alert rule in the organization was returned. From Grafana 13.1.0, any user can trigger this with a folder filter. The exposed data is rule configuration; data source credentials are not exposed.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-09-30T11:16:43.757Z",
"pubdate": "2026-09-30T11:16:43.757Z",
"executiveSummary": "This vulnerability is an Improper Access Control flaw within the Grafana alert rules API, enabling authenticated users to bypass folder-level permissions.\nThe issue manifests when a user requests a list of alert rules for folders they lack authorization to access; if the restricted folder set is empty, the application incorrectly lifts all access constraints, exposing every alert rule within the organization.\nStarting from Grafana 13.1.0, this can be triggered by providing a folder filter, further lowering the barrier for exploitation.\nThe primary impact is the unauthorized disclosure of sensitive alert rule configurations, which may reveal internal infrastructure monitoring strategies, alert logic, and organizational metadata.\nWhile the vulnerability does not expose data source credentials, the leakage of configuration metadata poses a significant risk to organizational security posture by facilitating reconnaissance.\nThe vulnerability requires an authenticated user account to exploit, though no specific elevated privileges are necessary, allowing any standard user to bypass security boundaries.\nMitigation involves updating to a patched version where access control logic for the alert rules API is strictly enforced regardless of the input parameters.",
"technicalDetails": "The vulnerability resides in the backend logic of the alert rules API list endpoint in Grafana. The root cause is a flaw in the authorization check logic that handles folder-based access control when a user attempts to retrieve alert rules.\nUnder normal operating conditions, the system should filter results based on the user's specific read permissions associated with the folder structure. However, the implementation contains a logic error where an empty set of authorized folders causes the system to erroneously bypass the filtering mechanism entirely rather than returning an empty list or an 'access denied' response.\nWhen the folder restriction logic evaluates to an empty set due to the user's limited permissions, the system defaults to an unconstrained state, inadvertently returning all alert rules existing within the organization.\nBeginning with Grafana 13.1.0, this flaw was exacerbated as users gained the ability to trigger this behavior using specific folder filter parameters in their API requests. An attacker can craft a request that includes a filter designed to trigger the misconfigured permission logic.\nThe exploitation flow follows these steps: 1) The attacker authenticates with the Grafana instance using a standard user account. 2) The attacker calls the alert rules API endpoint with a specifically crafted request designed to manipulate the folder filtering logic. 3) The backend, upon receiving the request, incorrectly evaluates the user's permission state due to the aforementioned flawed logic. 4) Instead of enforcing authorization, the backend proceeds to query the database for all alert rules without applying the mandatory security filters. 5) The API returns the full list of alert rules, including configurations from folders the attacker is not explicitly permitted to access.\nThe affected component is the alert rules API list endpoint. The vulnerability is present in Grafana versions 13.1.0 and subsequent releases that inherit this logic. Because the API operates over HTTP/HTTPS, the vulnerability is network-accessible to any user who can reach the Grafana web interface and authenticate successfully. The impact is limited to the unauthorized disclosure of alert configuration metadata and rule logic; it does not currently extend to the extraction of sensitive data source credentials or raw data stored within the monitored infrastructure."
}