SUSE-SU-2026:1524-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20261524-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1524-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:1524-1
Upstream
  • CVE-2025-3415
  • CVE-2025-61140
Related
Published
2026-04-21T09:26:09Z
Modified
2026-04-22T08:15:49.030922Z
Summary
Security update 5.1.3 for Multi-Linux Manager Client Tools
Details

This update fixes the following issues:

golang-github-lusitaniae-apache_exporter:

  • Internal changes to fix build issues with no impact for customers

golang-github-prometheus-prometheus:

  • Security issues fixed:

    • CVE-2026-27606: Fixed arbitrary file write via path traversal in rollup (bsc#1258893)
      • Bumped rollup to version 4.59.0
    • CVE-2026-25547: Fixed unbounded brace range expansion leading to excessive CPU and memory consumption (bsc#1257841)
      • Bumped brace-expansion to version 5.0.2
    • CVE-2026-1615, CVE-2025-61140 The old web UI is no longer built due to security issues (bsc#1257897, bsc#1257442)
    • CVE-2025-13465: Bumped lodash package to version 4.17.23 to fix prototype pollution vulnerability (bsc#1257329)
    • CVE-2026-33186: Fixed authorization bypass due to improper validation of the HTTP/2 :path pseudo-header (bsc#1260267)
      • Bumped google.golang.org/grpc to version 1.79.3

grafana:

  • Security issues fixed:

    • CVE-2026-21722: Public dashboards annotations: use dashboard timerange if time selection disabled (bsc#1258136)
    • CVE-2026-21721: Fixed access control by the dashboard permissions API (bsc#1257337)
    • CVE-2026-21720: Fixed unauthenticated DoS (bsc#1257349)
    • CVE-2025-3415: Fixed exposure of DingDing alerting integration URL to Viewer level users (bsc#1245302)
    • CVE-2026-26958: Bumped filippo.io/edwards25519 to version 1.1.1 (bsc#1258595)
    • CVE-2026-21725: Fixed missing UID when deleting datasource by name (bsc#1258873)
    • CVE-2026-21725: Fixed missing UID when deleting datasource by name (bsc#1258873)
    • CVE-2026-27876: Fixed remote arbitrary code execution via chained SQL Expressions (bsc#1261025)
    • CVE-2026-27877: Fixed information disclosure of data-source passwords via public dashboards (bsc#1261026)
    • CVE-2026-28375: Fixed denial of service via testdata data-source (bsc#1261029)
    • CVE-2026-27879: Fixed denial of service via resample query (bsc#1261027)
    • CVE-2026-33186: Fixed authorization bypass due to improper validation of the HTTP/2 :path pseudo-header (bsc#1260263)
    • CVE-2026-21724: Fixed authorization bypass allows modification of protected webhook URLs (bsc#1260878)
  • Version update from 11.5.10 to 11.6.14+security01 with the following highlighted changes and fixes:

    • Public Dashboards: Wired the public dashboard service to the HTTP server to ensure proper connectivity and availability
    • Authentication: Refined the redirect logic to ensure consistent behavior during login and logout sequences
    • Dashboard Reliability: Resolved a bug preventing single panels from rendering correctly when dashboard variables are referenced
    • Performance Boost: Introduced WebGL-powered geomaps for smoother map visualizations and removed blurred backgrounds from UI overlays to speed up the interface
    • One-Click Actions: Visualizations now support faster navigation via one-click links and actions
    • Alerting History: Added version history for alert rules, allowing you to track changes over time
    • Service Accounts: Automated the migration of old API keys to more secure Service Accounts upon startup
    • Cron Support: Annotations now support Cron syntax for more flexible scheduling
    • Identity and Auth: Hardened the Avatar feature (now requires sign-in) and fixed several login redirection issues when Grafana is hosted on a subpath
    • Data Source Support: Added support for Cloud Partner Prometheus data sources and improved Azure legend formatting
    • Alerting Limits: Added size limits for expanded notification templates to prevent system strain
    • RBAC: Integrated Role-Based Access Control (RBAC) into the Alertmanager via the reqAction field
    • Data Consistency: Fixed several issues with Graphite and InfluxDB regarding how variables are handled in repeated rows or nested queries
    • Dashboard Reliability:
      • Fixed bugs involving row repeats and 'self-referencing' data links
      • Fixed a bug preventing single panels from rendering correctly when dashboard variables are referenced
    • Alerting Fixes: Patched a critical 'panic' (crash) caused by a race condition in alert rules and fixed issues where contact points weren't working correctly
    • URL Handling: Fixed a bug where 'true' values in URL parameters weren't being read correctly

prometheus-blackbox_exporter:

  • Internal changes to fix build issues with no impact for customers

spacecmd:

  • Version 5.1.13-0
    • Update translation strings

uyuni-tools:

  • Version 5.1.26-0
    • Fixed applying PTF with images from RPMs (bsc#1252548)
    • Ssl Key file can miss if CA password is blank (bsc#1254154)
    • mgrpxy ssh tuning should happens before crypto policies (bsc#1254619)
    • Fixed default value for helm registry (bsc#1258927).
    • Remove hub register command
    • Optimize postgres migration disk space usage (bsc#1257447)
    • Added continuous database backup support (bsc#1250367)
    • Explicitly start proxy pods after operations (bsc#1258015)
    • Use static supportconfig name to avoid dynamic search (bsc#1257941)
    • Do not nest multiple tarball files and instead collect all files into one tarball (bsc#1252964)
    • Show where final tarball was generated (bsc#1259208)
    • Set proxy config file permissions (bsc#1257660)
  • Version 5.1.25-0
    • If PTF image doesn't exists, use the current service image (bsc#1258418)
References

Affected packages

SUSE:Multi Linux Manager Tools SLE-15
golang-github-lusitaniae-apache_exporter

Package

Name
golang-github-lusitaniae-apache_exporter
Purl
pkg:rpm/suse/golang-github-lusitaniae-apache_exporter&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-15

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.10-150002.3.6.1

Ecosystem specific

{
    "binaries": [
        {
            "mgrctl": "5.1.26-150002.3.12.1",
            "spacecmd": "5.1.13-150002.3.9.3",
            "grafana": "11.6.14+security01-150002.4.14.1",
            "firewalld-prometheus-config": "0.1-150002.3.8.1",
            "mgrctl-lang": "5.1.26-150002.3.12.1",
            "golang-github-prometheus-prometheus": "3.5.0-150002.3.8.1",
            "golang-github-lusitaniae-apache_exporter": "1.0.10-150002.3.6.1",
            "mgrctl-bash-completion": "5.1.26-150002.3.12.1",
            "mgrctl-zsh-completion": "5.1.26-150002.3.12.1",
            "prometheus-blackbox_exporter": "0.26.0-150002.3.6.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1524-1.json"
golang-github-prometheus-prometheus

Package

Name
golang-github-prometheus-prometheus
Purl
pkg:rpm/suse/golang-github-prometheus-prometheus&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-15

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.5.0-150002.3.8.1

Ecosystem specific

{
    "binaries": [
        {
            "mgrctl": "5.1.26-150002.3.12.1",
            "spacecmd": "5.1.13-150002.3.9.3",
            "grafana": "11.6.14+security01-150002.4.14.1",
            "firewalld-prometheus-config": "0.1-150002.3.8.1",
            "mgrctl-lang": "5.1.26-150002.3.12.1",
            "golang-github-prometheus-prometheus": "3.5.0-150002.3.8.1",
            "golang-github-lusitaniae-apache_exporter": "1.0.10-150002.3.6.1",
            "mgrctl-bash-completion": "5.1.26-150002.3.12.1",
            "mgrctl-zsh-completion": "5.1.26-150002.3.12.1",
            "prometheus-blackbox_exporter": "0.26.0-150002.3.6.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1524-1.json"
grafana

Package

Name
grafana
Purl
pkg:rpm/suse/grafana&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-15

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
11.6.14+security01-150002.4.14.1

Ecosystem specific

{
    "binaries": [
        {
            "mgrctl": "5.1.26-150002.3.12.1",
            "spacecmd": "5.1.13-150002.3.9.3",
            "grafana": "11.6.14+security01-150002.4.14.1",
            "firewalld-prometheus-config": "0.1-150002.3.8.1",
            "mgrctl-lang": "5.1.26-150002.3.12.1",
            "golang-github-prometheus-prometheus": "3.5.0-150002.3.8.1",
            "golang-github-lusitaniae-apache_exporter": "1.0.10-150002.3.6.1",
            "mgrctl-bash-completion": "5.1.26-150002.3.12.1",
            "mgrctl-zsh-completion": "5.1.26-150002.3.12.1",
            "prometheus-blackbox_exporter": "0.26.0-150002.3.6.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1524-1.json"
prometheus-blackbox_exporter

Package

Name
prometheus-blackbox_exporter
Purl
pkg:rpm/suse/prometheus-blackbox_exporter&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-15

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.26.0-150002.3.6.1

Ecosystem specific

{
    "binaries": [
        {
            "mgrctl": "5.1.26-150002.3.12.1",
            "spacecmd": "5.1.13-150002.3.9.3",
            "grafana": "11.6.14+security01-150002.4.14.1",
            "firewalld-prometheus-config": "0.1-150002.3.8.1",
            "mgrctl-lang": "5.1.26-150002.3.12.1",
            "golang-github-prometheus-prometheus": "3.5.0-150002.3.8.1",
            "golang-github-lusitaniae-apache_exporter": "1.0.10-150002.3.6.1",
            "mgrctl-bash-completion": "5.1.26-150002.3.12.1",
            "mgrctl-zsh-completion": "5.1.26-150002.3.12.1",
            "prometheus-blackbox_exporter": "0.26.0-150002.3.6.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1524-1.json"
spacecmd

Package

Name
spacecmd
Purl
pkg:rpm/suse/spacecmd&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-15

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.1.13-150002.3.9.3

Ecosystem specific

{
    "binaries": [
        {
            "mgrctl": "5.1.26-150002.3.12.1",
            "spacecmd": "5.1.13-150002.3.9.3",
            "grafana": "11.6.14+security01-150002.4.14.1",
            "firewalld-prometheus-config": "0.1-150002.3.8.1",
            "mgrctl-lang": "5.1.26-150002.3.12.1",
            "golang-github-prometheus-prometheus": "3.5.0-150002.3.8.1",
            "golang-github-lusitaniae-apache_exporter": "1.0.10-150002.3.6.1",
            "mgrctl-bash-completion": "5.1.26-150002.3.12.1",
            "mgrctl-zsh-completion": "5.1.26-150002.3.12.1",
            "prometheus-blackbox_exporter": "0.26.0-150002.3.6.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1524-1.json"
uyuni-tools

Package

Name
uyuni-tools
Purl
pkg:rpm/suse/uyuni-tools&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-15

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.1.26-150002.3.12.1

Ecosystem specific

{
    "binaries": [
        {
            "mgrctl": "5.1.26-150002.3.12.1",
            "spacecmd": "5.1.13-150002.3.9.3",
            "grafana": "11.6.14+security01-150002.4.14.1",
            "firewalld-prometheus-config": "0.1-150002.3.8.1",
            "mgrctl-lang": "5.1.26-150002.3.12.1",
            "golang-github-prometheus-prometheus": "3.5.0-150002.3.8.1",
            "golang-github-lusitaniae-apache_exporter": "1.0.10-150002.3.6.1",
            "mgrctl-bash-completion": "5.1.26-150002.3.12.1",
            "mgrctl-zsh-completion": "5.1.26-150002.3.12.1",
            "prometheus-blackbox_exporter": "0.26.0-150002.3.6.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1524-1.json"
SUSE:Multi Linux Manager Tools SLE-Micro-5
prometheus-blackbox_exporter

Package

Name
prometheus-blackbox_exporter
Purl
pkg:rpm/suse/prometheus-blackbox_exporter&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-Micro-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.26.0-150002.3.6.1

Ecosystem specific

{
    "binaries": [
        {
            "mgrctl-lang": "5.1.26-150002.3.12.1",
            "mgrctl": "5.1.26-150002.3.12.1",
            "mgrctl-bash-completion": "5.1.26-150002.3.12.1",
            "mgrctl-zsh-completion": "5.1.26-150002.3.12.1",
            "prometheus-blackbox_exporter": "0.26.0-150002.3.6.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1524-1.json"
uyuni-tools

Package

Name
uyuni-tools
Purl
pkg:rpm/suse/uyuni-tools&distro=SUSE%20Multi%20Linux%20Manager%20Tools%20SLE-Micro-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.1.26-150002.3.12.1

Ecosystem specific

{
    "binaries": [
        {
            "mgrctl-lang": "5.1.26-150002.3.12.1",
            "mgrctl": "5.1.26-150002.3.12.1",
            "mgrctl-bash-completion": "5.1.26-150002.3.12.1",
            "mgrctl-zsh-completion": "5.1.26-150002.3.12.1",
            "prometheus-blackbox_exporter": "0.26.0-150002.3.6.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1524-1.json"