
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-13719 is an information disclosure vulnerability in Grafana's alert rules API that allows authenticated users to enumerate alert rule configurations stored in folders they are not authorized to access. The flaw arises because when a user's readable folder set is empty, the folder-based access restriction is silently dropped, returning all alert rules in the organization. From Grafana 13.1.0 onward, any authenticated user can trigger this behavior using a folder filter parameter. Affected products include Grafana OSS and Grafana Enterprise versions 12.3.0–12.3.11, 12.4.0–12.4.11, 13.0.0–13.0.9, 13.1.0–13.1.6, and 13.2.0–13.2.2. It carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, Red Hat Bugzilla).
The root cause is an incorrect authorization check (CWE-863) combined with unintended information exposure (CWE-200) in the alert rules API list endpoint. When the access control logic computes the set of folders a user is permitted to read and that set is empty, the folder filter restriction is not applied — effectively bypassing the intended access control and returning all alert rules organization-wide. From Grafana 13.1.0, the attack surface broadened because any authenticated user can supply a folder filter parameter to trigger this bypass. Exploitation requires only a valid authenticated session and a network-reachable Grafana instance; no elevated privileges are needed (GitHub Advisory, Red Hat Bugzilla).
Successful exploitation allows any authenticated user to enumerate and read all alert rule configurations across the entire Grafana organization, regardless of folder-level access controls. The exposed data includes rule logic, conditions, and associated metadata; data source credentials are explicitly not exposed. While the confidentiality impact is limited to rule configuration, this information could assist attackers in understanding monitoring blind spots, evading detection, or planning further attacks within the environment (GitHub Advisory, Red Hat Bugzilla).
There is no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation at the time of disclosure. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires authentication (low-privilege user), making mass exploitation less likely, though the low attack complexity means any authenticated user on a vulnerable instance can trivially trigger the bypass (GitHub Advisory).
GET /api/ruler/{datasource_uid}/api/v1/rules or the equivalent Grafana alerting API path.?folderUID=<nonexistent_or_empty>) to trigger the authorization bypass regardless of folder permissions.GET requests to Grafana alert rules API endpoints (e.g., /api/ruler/, /api/v1/rules) from user accounts that do not normally access alerting features.Grafana has released patched versions addressing this vulnerability: 12.3.12 (12.3.x branch), 12.4.12 (12.4.x branch), 13.0.10 (13.0.x branch), 13.1.7 (13.1.x branch), and 13.2.3 (13.2.x branch). Organizations should upgrade to the appropriate patched release as the primary remediation. As a temporary workaround until patching is feasible, implement network-level access controls (e.g., firewall rules, reverse proxy authentication) to restrict access to the Grafana alert rules API endpoint to trusted users or IP ranges only (GitHub Advisory, Red Hat Bugzilla).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."