Database/Control plane, storage & DevOps
Grafana Alerting: Editor can exfiltrate contact point credentials by retargeting the test endpoint
Impact
A user holding alert.notifications:write or alert.notifications.receivers:test - granted by the Contact Point Writer role, which the basic Editor role includes - can edit a contact point created by someone else, point its endpoint URL at a server they control, and invoke the test function. The redacted secure settings are sent to that server, handing over the stored credentials: Slack tokens, webhook secrets, PagerDuty keys. In a GPU cluster this is the alerting path for node health, thermal and fabric events, so the stolen credentials give access to the operator's notification channels and whatever those integrations can reach. Grafana scores it 1.3 with exploit maturity unproven, but any Editor is enough, and credential theft outlasts the patch.
Who can reach it
Authenticated Grafana user with the Editor basic role (or any role carrying the contact point write/test permissions), over the network. Requires an outbound path from Grafana to an attacker-controlled host.
What to do
Upgrade to the Grafana release named in the advisory for CVE-2025-12141 and restart Grafana. Because the flaw leaks secrets rather than just granting access, rotate every credential stored in a contact point - Slack tokens, webhook URLs, API keys - after patching; patching alone does not undo prior exfiltration. Interim mitigation: strip contact point write and test permissions from the Editor role, and restrict Grafana's egress so a retargeted contact point cannot reach arbitrary hosts.
References
Related entries
- QCT (Quanta Cloud Technology) server security centre: QCT firmware is unmeasurable from public data despiteNCVD-2026-012-qct-quanta-cloud-technology-serv · QCT (Quanta Cloud Technology) server security centreUnscored
- Supermicro's public security advisory portal itself: An operator cannot programmatically track Supermicro firmwareNCVD-2026-013-supermicro-s-public-security-adv · Supermicro's public security advisory portal itselfUnscored
- Tyan / MiTAC Computing PSIRT: For Tyan, this vendor's firmware is unmeasurable from public dataNCVD-2026-014-tyan-mitac-computing-psirt · Tyan / MiTAC Computing PSIRTUnscored
- DDR4 / LPDDR4 DRAM - Target Row Refresh mitigation: Many-sided Rowhammer defeats the in-DRAM Target Row RefreshCVE-2020-10255 · DDR4 / LPDDR4 DRAM - Target Row Refresh mitigationUnscored
- Imagination PowerVR GPU driver - memory residue: An unprivileged application gets the GPU driver to hand backCVE-2021-0891 · Imagination PowerVR GPU driver - memory residueUnscored
- Linux HID/amd_sfh - shift out of bounds: A shift operation in the AMD Sensor Fusion Hub driver exceeds the maximumCVE-2023-53703 · Linux HID/amd_sfh - shift out of boundsUnscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.