GPU VulnDB

Database/Control plane, storage & DevOps

Grafana: alert rules API returns rules from folders the user cannot read

CVSS 4.3CVE-2026-13719Control plane, storage & DevOpscurated

Impact

Grafana is the observability front end for most GPU fleets, carrying DCGM metrics, fabric counters and capacity dashboards, and is commonly multi-tenant with folder permissions as the tenancy boundary. An authenticated user can list alert rules in folders they are not allowed to read; when the user's readable-folder set was empty the restriction was dropped entirely and every alert rule in the organization was returned. From Grafana 13.1.0 any user can trigger this with a folder filter. What leaks is rule configuration - thresholds, queries, label selectors and therefore the shape of the cluster and its tenants - not data source credentials. Treat it as a tenancy-boundary leak in the monitoring plane rather than a route to the GPU nodes themselves.

Who can reach it

Any authenticated Grafana user in the organization, over the network, via the alert rules API list endpoint. Authentication is required; no special role is needed, and from 13.1.0 a folder filter is enough.

What to do

Upgrade Grafana OSS or Enterprise to the fixed release named in the vendor advisory for CVE-2026-13719 and restart the Grafana service - a short control-plane restart, no node impact. If you cannot upgrade immediately, assume alert rule configuration is visible to every authenticated user and remove anything sensitive (hostnames, tenant identifiers, internal URLs) from rule definitions and annotations.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.