CVE-2026-15815

CVE-2026-15815 published: Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, writing arbitrary files and an executabl...

View full NVD advisory → ← Back to CVE watch