PT-2026-26315 · Grafana · Grafana Tempo
William_Goodfellow
·
Published
2026-03-16
·
Updated
2026-04-15
·
CVE-2026-28377
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Grafana Tempo versions prior to 2.10.3
Description
A flaw exists in Grafana Tempo that results in the exposure of the S3 SSE-C encryption key in plaintext. This exposure occurs through the
/status/config API endpoint. Successful exploitation could allow unauthorized users to obtain the key used to encrypt trace data stored in S3.Recommendations
Update to version 2.10.3 or later.
Fix
Cleartext Storage of Sensitive Information
Inadequate Encryption Strength
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Grafana Tempo