PT-2026-26315 · Grafana · Grafana Tempo

William_Goodfellow

·

Published

2026-03-16

·

Updated

2026-04-15

·

CVE-2026-28377

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Grafana Tempo versions prior to 2.10.3
Description A flaw exists in Grafana Tempo that results in the exposure of the S3 SSE-C encryption key in plaintext. This exposure occurs through the /status/config API endpoint. Successful exploitation could allow unauthorized users to obtain the key used to encrypt trace data stored in S3.
Recommendations Update to version 2.10.3 or later.

Fix

Cleartext Storage of Sensitive Information

Inadequate Encryption Strength

Weakness Enumeration

Related Identifiers

BDU:2026-06943
CLEANSTART-2026-KC83705
CVE-2026-28377
GHSA-FFQX-Q65F-36JF
OPENSUSE-SU-2026:10390-1

Affected Products

Grafana Tempo