{"schema_version":"1.7.5","id":"SUSE-SU-2026:2258-1","published":"2026-06-03T14:22:06Z","modified":"2026-06-04T09:00:04.530372201Z","related":["CVE-2025-29923","CVE-2026-21724","CVE-2026-21725","CVE-2026-26958","CVE-2026-27876","CVE-2026-27877","CVE-2026-27879","CVE-2026-28375","CVE-2026-33186","CVE-2026-33375","CVE-2026-34986","CVE-2026-41602"],"upstream":["CVE-2025-29923","CVE-2026-21724","CVE-2026-21725","CVE-2026-26958","CVE-2026-27876","CVE-2026-27877","CVE-2026-27879","CVE-2026-28375","CVE-2026-33186","CVE-2026-33375","CVE-2026-34986","CVE-2026-41602"],"summary":"Security update for grafana","details":"This update for grafana to version to 11.6.14+security01 fixes the following issues:\n\n- Security Fixes:\n\n  - CVE-2026-34986: Fixed unrecoverable error in JWE decryption that could lead to a denial of service (bsc#1262950)\n  - CVE-2026-41602: Fixed Integer Overflow or Wraparound vulnerability in Apache Thrift (bsc#1263501)\n  - CVE-2026-26958: Ensure that MultiScalarMult properly handles initialization and produces correct results \n    (bsc#1258595)\n  - CVE-2026-21725: Fixed missing UID when deleting datasource by name (bsc#1258873)\n  - CVE-2026-33375: Fixed denial of Service via out-of-memory exhaustion in MSSQL data source plugin (bsc#1260881)\n  - CVE-2026-27876: Fixed remote arbitrary code execution via chained SQL Expressions (bsc#1261025)\n  - CVE-2026-27877: Fixed information disclosure of data-source passwords via public dashboards (bsc#1261026)\n  - CVE-2026-28375: Fixed denial of service via testdata data-source (bsc#1261029)\n  - CVE-2026-27879: Fixed denial of service via resample query (bsc#1261027)\n  - CVE-2026-33186: Fixed authorization bypass due to improper validation of the HTTP/2 :path pseudo-header\n    (bsc#1260263)\n  - CVE-2026-21724: Fixed authorization bypass allows modification of protected webhook URLs (bsc#1260878)\n\n- Highlights of other changes and bug fixes:\n\n  - Version 11.6.13:\n\n    - Wire the public dashboard service to the HTTP server\n\n  - Version 11.6.12:\n\n    - Update authentication redirect logic\n    - Fixed single panel render with variable references\n\n  ","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262258-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258595"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258873"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259999"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260263"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260878"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260881"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261025"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261026"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261027"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261029"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262950"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263501"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-29923"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21724"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21725"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-26958"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27876"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27877"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27879"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28375"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33186"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33375"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34986"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41602"}]}