Grafana OnCall through 1.16.11 contains an...
Critical severity
Unreviewed
Published
Jul 16, 2026
to the GitHub Advisory Database
•
Updated Jul 16, 2026
Description
Published by the National Vulnerability Database
Jul 16, 2026
Published to the GitHub Advisory Database
Jul 16, 2026
Last updated
Jul 16, 2026
Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the internal plugin install endpoint using hardcoded default stack_id and org_id values present in the public source tree. Attackers can leverage the acquired token to authenticate against all internal API endpoints, create arbitrary Admin users via the user-context header bootstrap path, revoke the legitimate plugin token, and redirect OnCall-to-Grafana API calls to an attacker-controlled host by overwriting the organization's grafana_url and api_token.
References