{"schema_version":"1.7.5","id":"SUSE-SU-2026:1037-1","published":"2026-03-25T10:31:04Z","modified":"2026-03-26T09:02:58.752679Z","related":["CVE-2025-3415","CVE-2025-68156","CVE-2026-21720","CVE-2026-21721","CVE-2026-21722"],"upstream":["CVE-2025-3415","CVE-2025-68156","CVE-2026-21720","CVE-2026-21721","CVE-2026-21722"],"summary":"Security update for grafana","details":"This update for grafana fixes the following issues:\n\n- Security issues fixed:\n\n  - CVE-2026-21722: Public dashboards annotations: use dashboard timerange if time selection disabled (bsc#1258136)\n  - CVE-2026-21721: Fixed access control by the dashboard permissions API (bsc#1257337)\n  - CVE-2026-21720: Fixed unauthenticated DoS (bsc#1257349)\n  - CVE-2025-68156: Fixed potential DoS via unbounded recursion in builtin functions (bsc#1255340)\n  - CVE-2025-3415: Fixed exposure of DingDing alerting integration URL to Viewer level users (bsc#1245302)\n\n- Version update from 11.5.10 to 11.6.11 with the following highlighted changes and fixes:\n \n  - Performance Boost: Introduced WebGL-powered geomaps for smoother map visualizations and\n    removed blurred backgrounds from UI overlays to speed up the interface.\n  - One-Click Actions: Visualizations now support faster navigation via one-click links and actions.\n  - Alerting History: Added version history for alert rules, allowing you to track changes over time.\n  - Service Accounts: Automated the migration of old API keys to more secure Service Accounts upon startup.\n  - Cron Support: Annotations now support Cron syntax for more flexible scheduling.\n  - Identity and Auth: Hardened the Avatar feature (now requires sign-in) and fixed several login redirection issues \n    when Grafana is hosted on a subpath.\n  - Data Source Support: Added support for Cloud Partner Prometheus data sources and improved Azure legend formatting.\n  - Alerting Limits: Added size limits for expanded notification templates to prevent system strain.\n  - RBAC: Integrated Role-Based Access Control (RBAC) into the Alertmanager via the reqAction field.\n  - Data Consistency: Fixed several issues with Graphite and InfluxDB regarding how variables are handled in repeated\n    rows or nested queries.\n  - Dashboard Reliability: Resolved bugs involving row repeats and 'self-referencing' data links.\n  - Alerting Fixes: Patched a critical 'panic' (crash) caused by a race condition in alert rules and fixed issues where\n    contact points weren't working correctly.\n  - URL Handling: Fixed a bug where 'true' values in URL parameters weren't being read correctly\n","affected":[{"package":{"name":"grafana","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP7","purl":"pkg:rpm/suse/grafana&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"11.6.11-150200.3.83.1"}]}],"ecosystem_specific":{"binaries":[{"grafana":"11.6.11-150200.3.83.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1037-1.json"}},{"package":{"name":"grafana","ecosystem":"openSUSE:Leap 15.6","purl":"pkg:rpm/opensuse/grafana&distro=openSUSE%20Leap%2015.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"11.6.11-150200.3.83.1"}]}],"ecosystem_specific":{"binaries":[{"grafana":"11.6.11-150200.3.83.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1037-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20261037-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1245302"},{"type":"REPORT","url":"https://bugzilla.suse.com/1255340"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257337"},{"type":"REPORT","url":"https://bugzilla.suse.com/1257349"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258136"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-3415"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-68156"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21720"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21721"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21722"}]}