CVE-2026-13719: 
Grafana vulnerability analysis and mitigation

Overview

CVE-2026-13719 is an information disclosure vulnerability in Grafana's alert rules API that allows authenticated users to enumerate alert rule configurations stored in folders they are not authorized to access. The flaw arises because when a user's readable folder set is empty, the folder-based access restriction is silently dropped, returning all alert rules in the organization. From Grafana 13.1.0 onward, any authenticated user can trigger this behavior using a folder filter parameter. Affected products include Grafana OSS and Grafana Enterprise versions 12.3.0–12.3.11, 12.4.0–12.4.11, 13.0.0–13.0.9, 13.1.0–13.1.6, and 13.2.0–13.2.2. It carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is an incorrect authorization check (CWE-863) combined with unintended information exposure (CWE-200) in the alert rules API list endpoint. When the access control logic computes the set of folders a user is permitted to read and that set is empty, the folder filter restriction is not applied — effectively bypassing the intended access control and returning all alert rules organization-wide. From Grafana 13.1.0, the attack surface broadened because any authenticated user can supply a folder filter parameter to trigger this bypass. Exploitation requires only a valid authenticated session and a network-reachable Grafana instance; no elevated privileges are needed (GitHub Advisory, Red Hat Bugzilla).

Impact

Successful exploitation allows any authenticated user to enumerate and read all alert rule configurations across the entire Grafana organization, regardless of folder-level access controls. The exposed data includes rule logic, conditions, and associated metadata; data source credentials are explicitly not exposed. While the confidentiality impact is limited to rule configuration, this information could assist attackers in understanding monitoring blind spots, evading detection, or planning further attacks within the environment (GitHub Advisory, Red Hat Bugzilla).

Exploitability

There is no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation at the time of disclosure. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires authentication (low-privilege user), making mass exploitation less likely, though the low attack complexity means any authenticated user on a vulnerable instance can trivially trigger the bypass (GitHub Advisory).

Exploitation steps

  1. Authenticate: Obtain any valid low-privilege user account on the target Grafana instance (e.g., a viewer account).
  2. Identify the vulnerable endpoint: Locate the alert rules API list endpoint, typically at GET /api/ruler/{datasource_uid}/api/v1/rules or the equivalent Grafana alerting API path.
  3. Trigger the bypass (pre-13.1.0): Send an authenticated API request to the alert rules list endpoint. If the authenticated user has no readable folders assigned, the folder restriction is dropped server-side and all organization alert rules are returned in the response.
  4. Trigger the bypass (13.1.0+): Supply a folder filter parameter in the API request (e.g., ?folderUID=<nonexistent_or_empty>) to trigger the authorization bypass regardless of folder permissions.
  5. Enumerate alert rules: Parse the API response to collect all alert rule configurations across the organization, including rule names, conditions, thresholds, and associated folder metadata (GitHub Advisory).

Indicators of compromise

  • Network: Unusual or repeated authenticated GET requests to Grafana alert rules API endpoints (e.g., /api/ruler/, /api/v1/rules) from user accounts that do not normally access alerting features.
  • Logs: Grafana access logs showing alert rules API calls from low-privilege or viewer-role accounts, particularly with folder filter query parameters or from accounts with no folder read permissions.
  • Behavioral: A single user account making bulk or automated requests to the alert rules list endpoint in a short time window, suggesting enumeration activity.

Mitigation and workarounds

Grafana has released patched versions addressing this vulnerability: 12.3.12 (12.3.x branch), 12.4.12 (12.4.x branch), 13.0.10 (13.0.x branch), 13.1.7 (13.1.x branch), and 13.2.3 (13.2.x branch). Organizations should upgrade to the appropriate patched release as the primary remediation. As a temporary workaround until patching is feasible, implement network-level access controls (e.g., firewall rules, reverse proxy authentication) to restrict access to the Grafana alert rules API endpoint to trusted users or IP ranges only (GitHub Advisory, Red Hat Bugzilla).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

RHEL / CentOS

Affected

RHEL 8

Not Affected

RHEL 9

Not Affected

RHEL 10

grafana.src

Affected

Source: This report was generated using AI

Related Grafana vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-102990HIGH8.2
  • JavaScript logoJavaScript
  • rust-std-static
NoYesSep 30, 2026
CVE-2026-13720MEDIUM5.4
  • Grafana logoGrafana
  • grafana-selinux
NoYesSep 30, 2026
CVE-2026-81841MEDIUM5.3
  • Grafana logoGrafana
  • cpe:2.3:a:grafana:grafana
NoYesSep 29, 2026
CVE-2026-13719MEDIUM4.3
  • Grafana logoGrafana
  • cpe:2.3:a:grafana:grafana
NoYesSep 30, 2026
CVE-2026-81842MEDIUM4.3
  • Grafana logoGrafana
  • grafana-cloudwatch
NoYesSep 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management