Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ SUSE-SU-2026:1037-1 — grafana (CVE-2026-21722 +4 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for grafana

This update for grafana fixes the following issues:

  • Security issues fixed:
  • CVE-2026-21722: Public dashboards annotations: use dashboard timerange if time selection disabled (bsc#1258136)
  • CVE-2026-21721: Fixed access control by the dashboard permissions API (bsc#1257337)
  • CVE-2026-21720: Fixed unauthenticated DoS (bsc#1257349)
  • CVE-2025-68156: Fixed potential DoS via unbounded recursion in builtin functions (bsc#1255340)
  • CVE-2025-3415: Fixed exposure of DingDing alerting integration URL to Viewer level users (bsc#1245302)
  • Version update from 11.5.10 to 11.6.11 with the following highlighted changes and fixes:
  • Performance Boost: Introduced WebGL-powered geomaps for smoother map visualizations and

removed blurred backgrounds from UI overlays to speed up the interface.

  • One-Click Actions: Visualizations now support faster navigation via one-click links and actions.
  • Alerting History: Added version history for alert rules, allowing you to track changes over time.
  • Service Accounts: Automated the migration of old API keys to more secure Service Accounts upon startup.
  • Cron Support: Annotations now support Cron syntax for more flexible scheduling.
  • Identity and Auth: Hardened the Avatar feature (now requires sign-in) and fixed several login redirection issues

when Grafana is hosted on a subpath.

  • Data Source Support: Added support for Cloud Partner Prometheus data sources and improved Azure legend formatting.
  • Alerting Limits: Added size limits for expanded notification templates to prevent system strain.
  • RBAC: Integrated Role-Based Access Control (RBAC) into the Alertmanager via the reqAction field.
  • Data Consistency: Fixed several issues with Graphite and InfluxDB regarding how variables are handled in repeated

rows or nested queries.

  • Dashboard Reliability: Resolved bugs involving row repeats and 'self-referencing' data links.
  • Alerting Fixes: Patched a critical 'panic' (crash) caused by a race condition in alert rules and fixed issues where

contact points weren't working correctly.

  • URL Handling: Fixed a bug where 'true' values in URL parameters weren't being read correctly

Affected software

SUSE-SU-2026:1037-1 is recorded against 1 package.

  • grafana (fixed in 11.6.11-150200.3.83.1)

Timeline and source

Published on 25 March 2026 and last revised on 26 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-03-25
Updated 2026-08-20
Modified 2026-03-26
Fix URL N/A

Affected Packages

Software From version Fixed in
grafana 11.6.11-150200.3.83.1

Similar Threats

Free Vulnerability Check

Is your site affected by SUSE-SU-2026:1037-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2026:1037-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.