CVE-2026-13719 PUBLISHED

Alert rules in restricted folders disclosed via the alert rules list API

Assigner: GRAFANA
Reserved: 29.06.2026 Published: 30.09.2026 Updated: 30.09.2026

An authenticated user can list alert rules stored in folders they are not allowed to read through the alert rules API list endpoint. When the set of folders the user may read was empty, the folder restriction was dropped and every alert rule in the organization was returned. From Grafana 13.1.0, any user can trigger this with a folder filter. The exposed data is rule configuration; data source credentials are not exposed.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 4.3

Product Status

Vendor Grafana
Product Grafana Enterprise
Versions Default: unaffected
  • affected from 12.3.0 to 12.3.11 (incl.)
  • affected from 12.4.0 to 12.4.12 (excl.)
  • affected from 13.0.0 to 13.0.10 (excl.)
  • affected from 13.1.0 to 13.1.7 (excl.)
  • affected from 13.2.0 to 13.2.3 (excl.)
Vendor Grafana
Product Grafana OSS
Versions Default: unaffected
  • affected from 12.3.0 to 12.3.11 (incl.)
  • affected from 12.4.0 to 12.4.12 (excl.)
  • affected from 13.0.0 to 13.0.10 (excl.)
  • affected from 13.1.0 to 13.1.7 (excl.)
  • affected from 13.2.0 to 13.2.3 (excl.)

Credits

  • mon3m finder

References

Problem Types

  • CWE-863 CWE
  • CWE-200 CWE