CVE-2026-17183

CVE-2026-17183 CVE Record

An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a server-side expression while referencing a real datasource UID (incorrect authorization). This can expose data accessible through Grafana's configured datasource credentials to users who lack permission to query that datasource.


We have discovered 538 live websites that are affected by CVE-2026-17183.

Run a Free Instant Scan




Affected Software

Product  Grafana
Category Analytics
Vulnerable Domains538 live websites (99% of Grafana install base)
Vulnerable Versions
  • from 8.4 through 12.3.11
  • from 12.4 through 12.4.9
  • from 13 through 13.0.7
  • from 13.1 through 13.1.4
Vulnerable Versions Count61 versions ( 80% of all versions)


Common Weakness Enumeration

CWE-863 Incorrect Authorization



Details

  • Published - Aug 19, 2026
  • Updated - Aug 27, 2026

Credits

  • czarflix (finder)

Website Distribution by Country

Number of websites using CVE-2026-17183
United States256 websites



Germany81 websites
France44 websites
Russia20 websites
Singapore17 websites
Switzerland15 websites
China13 websites
Netherlands9 websites
Czech Republic9 websites

Website Distribution by TLD

Number of websites using CVE-2026-17183
.com148 websites
.io94 websites
.net53 websites
.org33 websites
.de32 websites
.ch15 websites
.ru15 websites
.fr11 websites
.eu9 websites
.cz7 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-17183

Top websites that are affected by CVE-2026-17183. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.*******.io France**,***
**.*****************.com Germany**,***
********.kz Kazakhstan***,***
***.********.****.io United States***,***
********.info France***,***
********.com United States***,***
**********.********.****.io United States***,***
***.********.****.io United States*,***,***
*******.***.ch Switzerland*,***,***
*******.net United States*,***,***
See full domain list

FAQ

CVE-2026-17183 is Incorrect Authorization in Grafana
A total of 538 websites have been identified as vulnerable to CVE-2026-17183, based on global website indexing conducted by WebTechSurvey.
The Grafana is affected by the CVE-2026-17183 vulnerability.
Grafana versions up to 13.1.4 are vulnerable to CVE-2026-17183.
CVE-2026-17183 is resolved in version 13.1.4 of Grafana.