PT-2026-21013 · Grafana · Loki

Published

2026-01-26

·

Updated

2026-05-18

·

CVE-2026-21726

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Loki (affected versions not specified)
Description An issue in the log aggregation and storage system exists due to improper restriction of the directory path name. By using double encoding to bypass validation of the namespace parameter for path traversal sequences after a single URL decode, a remote attacker can gain unauthorized access to protected information via the Ruler API endpoint '/loki/api/v1/rules/{namespace}'.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Open Redirect

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2026-02012
CLEANSTART-2026-ET12387
CLEANSTART-2026-GN78570
CLEANSTART-2026-JG72006
CLEANSTART-2026-NR54556
CLEANSTART-2026-QV77143
CLEANSTART-2026-VT65447
CVE-2026-21726
GHSA-497X-RRR9-68JP

Affected Products

Loki