No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as possible to improve your deployments' security.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 27 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 27 Mar 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as possible to improve your deployments' security. | |
| Title | Public dashboards discloses all direct mode datasources | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GRAFANA
Published:
Updated: 2026-03-27T14:56:34.782Z
Reserved: 2026-02-24T14:30:17.726Z
Link: CVE-2026-27877
Updated: 2026-03-27T14:54:26.882Z
Status : Received
Published: 2026-03-27T15:16:51.050
Modified: 2026-03-27T15:16:51.050
Link: CVE-2026-27877
No data.
OpenCVE Enrichment
No data.
No weakness.