{"schema_version":"1.7.5","id":"openSUSE-SU-2026:20940-1","published":"2026-06-10T12:02:03Z","modified":"2026-06-13T18:24:19.477495413Z","related":["CVE-2025-29923","CVE-2025-30153","CVE-2026-21724","CVE-2026-21725","CVE-2026-26958","CVE-2026-27876","CVE-2026-27877","CVE-2026-27879","CVE-2026-28374","CVE-2026-28375","CVE-2026-28376","CVE-2026-28379","CVE-2026-28380","CVE-2026-28383","CVE-2026-33186","CVE-2026-33375","CVE-2026-33376","CVE-2026-33377","CVE-2026-33378","CVE-2026-33380","CVE-2026-33381","CVE-2026-34986","CVE-2026-39821","CVE-2026-41602"],"upstream":["CVE-2025-29923","CVE-2025-30153","CVE-2026-21724","CVE-2026-21725","CVE-2026-26958","CVE-2026-27876","CVE-2026-27877","CVE-2026-27879","CVE-2026-28374","CVE-2026-28375","CVE-2026-28376","CVE-2026-28379","CVE-2026-28380","CVE-2026-28383","CVE-2026-33186","CVE-2026-33375","CVE-2026-33376","CVE-2026-33377","CVE-2026-33378","CVE-2026-33380","CVE-2026-33381","CVE-2026-34986","CVE-2026-39821","CVE-2026-41602"],"summary":"Security update for grafana","details":"This update for grafana fixes the following issues:\n\nChanges in grafana:\n\n- CVE-2026-39821: Fix validation bypass and privilege escalation by\n  updating golang.org/x/net to version 0.55.0 (bsc#1266600)\n\n- Update to version 11.6.14+security-04:\n  Security:\n  * CVE-2026-28374: Fix insecure direct object reference in\n    Annotations API (bsc#1265290)\n  * CVE-2026-28376: Fix unbounded memory allocation in Grafana Live\n    push endpoint (bsc#1265289)\n  * CVE-2026-28383: Fix unbounded memory allocation in Grafana\n    plugin resources (bsc#1265286)\n  * CVE-2026-28380: Fix broken access control in Snapshot API\n    (bsc#1265287)\n  * CVE-2026-33376: Fix Auth Proxy IPv6 whitelist bypass\n    (bsc#1265285)\n  * CVE-2026-28379: Fix viewer-triggered race condition in\n    Grafana Live (bsc#1265288)\n  * CVE-2026-33377: Fix dashboard Editor Privilege Escalation\n    (bsc#1265284)\n  * CVE-2026-33378: Fix OOM exception in Grafana Data Source Plugin\n    (bsc#1265283)\n  * CVE-2026-33381: Prevent users from generating Service Account\n    tokens after permissions removal (bsc#1265281)\n  * CVE-2026-33380: Fix vulnerability in SQL Expressions allowing\n    an authenticated attacker to read arbitrary files from the\n    Grafana server’s filesystem (bsc#1265282)\n\n- CVE-2026-34986: Fix panic in JWE decryption (bsc#1262950)\n- CVE-2026-41602: Fix Integer Overflow or Wraparound vulnerability\n  in Apache Thrift (bsc#1263501)\n\n- CVE-2026-26958: Bump filippo.io/edwards25519 to version 1.1.1\n  (bsc#1258595)\n- CVE-2026-21725: Fix missing UID when deleting datasource by name\n  (bsc#1258873)\n\n- Update to version 11.6.14+security-01:\n  Security:\n  * CVE-2026-33375: Fix denial of Service via out-of-memory\n    exhaustion in MSSQL data source plugin (bsc#1260881)\n\n- Update to version 11.6.14:\n  Security:\n  * CVE-2026-27876: Fix remote arbitrary code execution via chained\n    SQL Expressions (bsc#1261025)\n  * CVE-2026-27877: Fix information disclosure of data-source\n    passwords via public dashboards (bsc#1261026)\n  * CVE-2026-28375: Fix denial of service via testdata data-source\n    (bsc#1261029)\n  * CVE-2026-27879: Fix denial of service via resample query\n    (bsc#1261027)\n  * CVE-2026-33186: Fix authorization bypass due to improper\n    validation of the HTTP/2 :path pseudo-header (bsc#1260263)\n  * CVE-2026-21724: Fix authorization bypass allows modification of\n    protected webhook URLs (bsc#1260878)\n\n- Update to version 11.6.13:\n  Enhancement:\n  * Wire the public dashboard service to the HTTP server\n\n- Update to version 11.6.12:\n  Enhancement:\n  * Update authentication redirect logic\n  Bug fix:\n  * Fix single panel render with variable references\n","affected":[{"package":{"name":"grafana","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/grafana&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"11.6.14+security04-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"grafana":"11.6.14+security04-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20940-1.json"}}],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258595"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258873"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259999"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260263"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260878"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260881"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261025"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261026"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261027"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261029"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262950"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263501"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264764"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265281"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265282"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265283"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265284"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265285"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265286"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265287"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265288"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265289"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265290"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266600"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-29923"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-30153"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21724"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21725"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-26958"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27876"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27877"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27879"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28374"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28375"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28376"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28379"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28380"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28383"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33186"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33375"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33376"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33377"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33378"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33380"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33381"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34986"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39821"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41602"}]}