openSUSE-SU-2026:20940-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20940-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:20940-1
Upstream
Related
Published
2026-06-10T12:02:03Z
Modified
2026-06-13T18:24:19Z
Summary
Security update for grafana
Details

This update for grafana fixes the following issues:

Changes in grafana:

  • CVE-2026-39821: Fix validation bypass and privilege escalation by updating golang.org/x/net to version 0.55.0 (bsc#1266600)

  • Update to version 11.6.14+security-04: Security:

    • CVE-2026-28374: Fix insecure direct object reference in Annotations API (bsc#1265290)
    • CVE-2026-28376: Fix unbounded memory allocation in Grafana Live push endpoint (bsc#1265289)
    • CVE-2026-28383: Fix unbounded memory allocation in Grafana plugin resources (bsc#1265286)
    • CVE-2026-28380: Fix broken access control in Snapshot API (bsc#1265287)
    • CVE-2026-33376: Fix Auth Proxy IPv6 whitelist bypass (bsc#1265285)
    • CVE-2026-28379: Fix viewer-triggered race condition in Grafana Live (bsc#1265288)
    • CVE-2026-33377: Fix dashboard Editor Privilege Escalation (bsc#1265284)
    • CVE-2026-33378: Fix OOM exception in Grafana Data Source Plugin (bsc#1265283)
    • CVE-2026-33381: Prevent users from generating Service Account tokens after permissions removal (bsc#1265281)
    • CVE-2026-33380: Fix vulnerability in SQL Expressions allowing an authenticated attacker to read arbitrary files from the Grafana server’s filesystem (bsc#1265282)
  • CVE-2026-34986: Fix panic in JWE decryption (bsc#1262950)

  • CVE-2026-41602: Fix Integer Overflow or Wraparound vulnerability in Apache Thrift (bsc#1263501)

  • CVE-2026-26958: Bump filippo.io/edwards25519 to version 1.1.1 (bsc#1258595)

  • CVE-2026-21725: Fix missing UID when deleting datasource by name (bsc#1258873)

  • Update to version 11.6.14+security-01: Security:

    • CVE-2026-33375: Fix denial of Service via out-of-memory exhaustion in MSSQL data source plugin (bsc#1260881)
  • Update to version 11.6.14: Security:

    • CVE-2026-27876: Fix remote arbitrary code execution via chained SQL Expressions (bsc#1261025)
    • CVE-2026-27877: Fix information disclosure of data-source passwords via public dashboards (bsc#1261026)
    • CVE-2026-28375: Fix denial of service via testdata data-source (bsc#1261029)
    • CVE-2026-27879: Fix denial of service via resample query (bsc#1261027)
    • CVE-2026-33186: Fix authorization bypass due to improper validation of the HTTP/2 :path pseudo-header (bsc#1260263)
    • CVE-2026-21724: Fix authorization bypass allows modification of protected webhook URLs (bsc#1260878)
  • Update to version 11.6.13: Enhancement:

    • Wire the public dashboard service to the HTTP server
  • Update to version 11.6.12: Enhancement:

    • Update authentication redirect logic Bug fix:
    • Fix single panel render with variable references
References

Affected packages

openSUSE:Leap 16.0 / grafana

Package

Name
grafana
Purl
pkg:rpm/opensuse/grafana&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
11.6.14+security04-bp160.1.1

Ecosystem specific

{
    "binaries": [
        {
            "grafana": "11.6.14+security04-bp160.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20940-1.json"