CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-28381

highcovered by 1 sourcefirst seen 2026-07-20
A remote, authenticated attacker can exploit a vulnerability in Grafana to manipulate files.

CSIRTS triage

What
A vulnerability in Grafana allows a remote, authenticated attacker to manipulate files.
Who is affected
Authenticated users of Grafana are affected by this vulnerability.
Urgency
Remediation is high priority due to the potential for file manipulation by attackers.
Action
Update to the latest version of Grafana to mitigate this vulnerability.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-28381

Get an email if CVE-2026-28381 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-28381

CVE.org record

Embed the live status

CVE-2026-28381 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-28381 status](https://www.csirts.com/badge/CVE-2026-28381)](https://www.csirts.com/cve/CVE-2026-28381)