CVE-2026-27877
When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards.
CVSS
6.5
Medium
EPSS
0.3%
p23
KEV
—
Exploit Today
7
0-100
Published: Mar 27, 2026 · Last modified: Jul 15, 2026 · CWE-312 · CWE-201
0.3%EPSS · 30 days0.3%
2026-08-132026-09-10
When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as possible to improve your deployments' security.
- grafana.comhttps://grafana.com/security/security-advisories/cve-2026-27877
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:10223
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:10226
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:11416
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:11417
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:19134
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:19352
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-27877
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2452293
- grafana.comhttps://grafana.com/security/security-advisories/cve-2026-27877
- security.access.redhat.comhttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27877.json
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-41307.1 HIG—
——0There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear. This vulnerability affects NI SystemLink and NI SystemLink Server 2026 Q3 and prior versions.23hCVE-2026-818047.5 HIG—
——0Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore & Migration <= 2.4.2 versions.21hCVE-2026-78374—43.6%
——13Joomla Extension - joomlart.com - Open mail relay via contact AJAX endpoint in T4 Page Builder extension < 2.3.0 - The front-end JSON editor endpoint exposes an action called contact that requires no authentication, no CSRF token, no captcha (when no captcha plugin is enabled) and has no rate limiting. The attacker fully controls the recipient, subject and HTML body, and the mail is sent from the site's configured sender identity (mailfrom/fromname).1dCVE-2026-78303—36.1%
——11Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4 - Booking inquiries previously relied on client-submitted hidden fields for recipient routing, allowing potential email manipulation.1dCVE-2026-870156.8 MED20.3%
——6Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.27 until 0.11.1, backend/open_webui/utils/tools.py captured a cookie jar from the enclosing connection loop instead of binding it to each external tool callable. When multiple tool servers were attached and a session or system OAuth connection was processed last, a request to a different server configured for bearer authentication could include the calling user's Open WebUI session cookies, allowing that server's operator to reuse the session and take over the account. This issue is fixed in version 0.11.1.1dCVE-2026-658126.8 MED40.4%
——12Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.3d