Grafana: Grafana: Information disclosure of secure settings via contact point modification

cve CVE-2025-12141 2 sources, 2 claims · Watch

Red Hat writes:
Grafana: Grafana: Information disclosure of secure settings via contact point modification the claim
Severity they disagree
MEDIUM NVD
low Red Hat
CVSS they disagree
6.5 NVD
5 Red Hat
Vendor
Grafana NVD
Product
Grafana Alerting NVD
CWE
CWE-200 NVD
CWE-266 Red Hat

How far exploitation has got

  1. No public code known
  2. Proof of concept
  3. Proof of concept, verified
  4. A Metasploit module
  5. Exploited in the wild
  6. Used in ransomware campaigns

Why the CVSS differs

MetricNVDRed Hat
Attack vector AVnetwork Nnetwork N
Attack complexity AClow Llow L
Privileges required PRlow Llow L
User interaction UInone Nnone N
Scope Sunchanged Uchanged C
Confidentiality Chigh Hlow L
Integrity Inone Nnone N
Availability Anone Nnone N

Each source scores the same vulnerability from what it judges the attack to need. The rows marked are where they judge it differently.

Timeline

2026-04-15first spoke of it: In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role "Contact Point Writer", which is part of the basic role Editor - can edit contact points created by other users, modify the endpoint URL to a controlled server. By invoking the test functionality, attackers can capture and extract redacted secure settings, such as authentication credentials for third-party services (e.g., Slack tokens). This leads to unauthorized access and potential compromise of external integrations.NVD
2026-04-15first spoke of it: Grafana: Grafana: Information disclosure of secure settings via contact point modificationRed Hat

What it is to other things

affectsgrafana/grafana
NVD
made_bygrafana
NVD

In words only, so not counted until a person confirms one:

affectsgrafana/grafana_alerting
NVD says “Grafana · Grafana Alerting”
Every value, with what each source said and its receipt
PropertySourceSaidMeans here
Automatable
automatable
NVDyes
An attacker can reliably run all of the kill chain's first four steps without a person.
receipt
Source
NVD
Its words
yes
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].automatable
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCyes
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Grafana Alerting",
            "repo": "https://github.com/grafana/grafana",
            "vendor": "Grafana",
            "versions": [
              {
                "lessThanOrEqual": "12.3.0",
                "status": "affected",
                "version": "8.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@grafana.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1DDFD2FD-7573-4993-8C82-2DBA97D95956",
                "versionEndIncluding": "12.3.0",
                "versionStartIncluding": "8.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role \"Contact Point Writer\", which is part of the basic role Editor - can edit contact points created by other users, modify the endpoint URL to a controlled server. By invoking the test functionality, attackers can capture and extract redacted secure settings, such as authentication credentials for third-party services (e.g., Slack tokens). This leads to unauthorized access and potential compromise of external integrations."
      },
      {
        "lang": "es",
        "value": "En el sistema de alertas de Grafana, los usuarios con permisos de edición para un punto de contacto, específicamente los permisos 'alert.notifications:write' o 'alert.notifications.receivers:test' que se otorgan como parte del rol fijo 'Contact Point Writer', que forma parte del rol básico Editor - pueden editar puntos de contacto creados por otros usuarios, modificar la URL del endpoint a un servidor controlado. Al invocar la funcionalidad de prueba, los atacantes pueden capturar y extraer configuraciones seguras redactadas, como credenciales de autenticación para servicios de terceros (p. ej., tokens de Slack). Esto conduce a acceso no autorizado y a la posible compromiso de integraciones externas."
      }
    ],
    "id": "CVE-2025-12141",
    "lastModified": "2026-09-30T22:10:00.273",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "YES",
            "Recovery": "NOT_DEFINED",
            "Safety": "NEGLIGIBLE",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 1.3,
            "baseSeverity": "LOW",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "UNREPORTED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "LOW",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security@grafana.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-12141",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-04-15T18:45:45.527327Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-04-15T16:16:33.040",
    "references": [
      {
        "source": "security@grafana.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://grafana.com/security/security-advisories/cve-2025-12141/"
      }
    ],
    "sourceIdentifier": "security@grafana.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-200"
          }
        ],
        "source": "security@grafana.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
conflict
NVD6.5
receipt
Source
NVD
Its words
6.5
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Grafana Alerting",
            "repo": "https://github.com/grafana/grafana",
            "vendor": "Grafana",
            "versions": [
              {
                "lessThanOrEqual": "12.3.0",
                "status": "affected",
                "version": "8.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@grafana.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1DDFD2FD-7573-4993-8C82-2DBA97D95956",
                "versionEndIncluding": "12.3.0",
                "versionStartIncluding": "8.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role \"Contact Point Writer\", which is part of the basic role Editor - can edit contact points created by other users, modify the endpoint URL to a controlled server. By invoking the test functionality, attackers can capture and extract redacted secure settings, such as authentication credentials for third-party services (e.g., Slack tokens). This leads to unauthorized access and potential compromise of external integrations."
      },
      {
        "lang": "es",
        "value": "En el sistema de alertas de Grafana, los usuarios con permisos de edición para un punto de contacto, específicamente los permisos 'alert.notifications:write' o 'alert.notifications.receivers:test' que se otorgan como parte del rol fijo 'Contact Point Writer', que forma parte del rol básico Editor - pueden editar puntos de contacto creados por otros usuarios, modificar la URL del endpoint a un servidor controlado. Al invocar la funcionalidad de prueba, los atacantes pueden capturar y extraer configuraciones seguras redactadas, como credenciales de autenticación para servicios de terceros (p. ej., tokens de Slack). Esto conduce a acceso no autorizado y a la posible compromiso de integraciones externas."
      }
    ],
    "id": "CVE-2025-12141",
    "lastModified": "2026-09-30T22:10:00.273",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "YES",
            "Recovery": "NOT_DEFINED",
            "Safety": "NEGLIGIBLE",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 1.3,
            "baseSeverity": "LOW",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "UNREPORTED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "LOW",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security@grafana.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-12141",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-04-15T18:45:45.527327Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-04-15T16:16:33.040",
    "references": [
      {
        "source": "security@grafana.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://grafana.com/security/security-advisories/cve-2025-12141/"
      }
    ],
    "sourceIdentifier": "security@grafana.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-200"
          }
        ],
        "source": "security@grafana.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
conflict
Red Hat5
receipt
Source
Red Hat
Its words
5.0
Read by
field:cvss3_score
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-12141",
  "CWE": "CWE-266",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2458704",
  "bugzilla_description": "Grafana: Grafana: Information disclosure of secure settings via contact point modification",
  "cvss3_score": "5.0",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-04-15T14:59:41Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-12141.json",
  "severity": "low"
}
—
Cvss4
cvss4
NVD1.3
receipt
Source
NVD
Its words
1.3
Read by
field:cve.metrics.cvssMetricV40[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV40[].cvssData.baseScore
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTC1.3
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Grafana Alerting",
            "repo": "https://github.com/grafana/grafana",
            "vendor": "Grafana",
            "versions": [
              {
                "lessThanOrEqual": "12.3.0",
                "status": "affected",
                "version": "8.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@grafana.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1DDFD2FD-7573-4993-8C82-2DBA97D95956",
                "versionEndIncluding": "12.3.0",
                "versionStartIncluding": "8.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role \"Contact Point Writer\", which is part of the basic role Editor - can edit contact points created by other users, modify the endpoint URL to a controlled server. By invoking the test functionality, attackers can capture and extract redacted secure settings, such as authentication credentials for third-party services (e.g., Slack tokens). This leads to unauthorized access and potential compromise of external integrations."
      },
      {
        "lang": "es",
        "value": "En el sistema de alertas de Grafana, los usuarios con permisos de edición para un punto de contacto, específicamente los permisos 'alert.notifications:write' o 'alert.notifications.receivers:test' que se otorgan como parte del rol fijo 'Contact Point Writer', que forma parte del rol básico Editor - pueden editar puntos de contacto creados por otros usuarios, modificar la URL del endpoint a un servidor controlado. Al invocar la funcionalidad de prueba, los atacantes pueden capturar y extraer configuraciones seguras redactadas, como credenciales de autenticación para servicios de terceros (p. ej., tokens de Slack). Esto conduce a acceso no autorizado y a la posible compromiso de integraciones externas."
      }
    ],
    "id": "CVE-2025-12141",
    "lastModified": "2026-09-30T22:10:00.273",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "YES",
            "Recovery": "NOT_DEFINED",
            "Safety": "NEGLIGIBLE",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 1.3,
            "baseSeverity": "LOW",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "UNREPORTED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "LOW",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security@grafana.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-12141",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-04-15T18:45:45.527327Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-04-15T16:16:33.040",
    "references": [
      {
        "source": "security@grafana.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://grafana.com/security/security-advisories/cve-2025-12141/"
      }
    ],
    "sourceIdentifier": "security@grafana.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-200"
          }
        ],
        "source": "security@grafana.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Cvss4 vector
cvss4_vector
NVDCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:X/RE:X/U:X
receipt
Source
NVD
Its words
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:X/RE:X/U:X
Read by
field:cve.metrics.cvssMetricV40[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV40[].cvssData.vectorString
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:X/RE:X/U:X
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Grafana Alerting",
            "repo": "https://github.com/grafana/grafana",
            "vendor": "Grafana",
            "versions": [
              {
                "lessThanOrEqual": "12.3.0",
                "status": "affected",
                "version": "8.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@grafana.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1DDFD2FD-7573-4993-8C82-2DBA97D95956",
                "versionEndIncluding": "12.3.0",
                "versionStartIncluding": "8.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role \"Contact Point Writer\", which is part of the basic role Editor - can edit contact points created by other users, modify the endpoint URL to a controlled server. By invoking the test functionality, attackers can capture and extract redacted secure settings, such as authentication credentials for third-party services (e.g., Slack tokens). This leads to unauthorized access and potential compromise of external integrations."
      },
      {
        "lang": "es",
        "value": "En el sistema de alertas de Grafana, los usuarios con permisos de edición para un punto de contacto, específicamente los permisos 'alert.notifications:write' o 'alert.notifications.receivers:test' que se otorgan como parte del rol fijo 'Contact Point Writer', que forma parte del rol básico Editor - pueden editar puntos de contacto creados por otros usuarios, modificar la URL del endpoint a un servidor controlado. Al invocar la funcionalidad de prueba, los atacantes pueden capturar y extraer configuraciones seguras redactadas, como credenciales de autenticación para servicios de terceros (p. ej., tokens de Slack). Esto conduce a acceso no autorizado y a la posible compromiso de integraciones externas."
      }
    ],
    "id": "CVE-2025-12141",
    "lastModified": "2026-09-30T22:10:00.273",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "YES",
            "Recovery": "NOT_DEFINED",
            "Safety": "NEGLIGIBLE",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 1.3,
            "baseSeverity": "LOW",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "UNREPORTED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "LOW",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security@grafana.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-12141",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-04-15T18:45:45.527327Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-04-15T16:16:33.040",
    "references": [
      {
        "source": "security@grafana.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://grafana.com/security/security-advisories/cve-2025-12141/"
      }
    ],
    "sourceIdentifier": "security@grafana.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-200"
          }
        ],
        "source": "security@grafana.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS vector
cvss_vector
not compared
NVDCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
receipt
Source
NVD
Its words
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV31[].cvssData.vectorString
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Grafana Alerting",
            "repo": "https://github.com/grafana/grafana",
            "vendor": "Grafana",
            "versions": [
              {
                "lessThanOrEqual": "12.3.0",
                "status": "affected",
                "version": "8.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@grafana.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1DDFD2FD-7573-4993-8C82-2DBA97D95956",
                "versionEndIncluding": "12.3.0",
                "versionStartIncluding": "8.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role \"Contact Point Writer\", which is part of the basic role Editor - can edit contact points created by other users, modify the endpoint URL to a controlled server. By invoking the test functionality, attackers can capture and extract redacted secure settings, such as authentication credentials for third-party services (e.g., Slack tokens). This leads to unauthorized access and potential compromise of external integrations."
      },
      {
        "lang": "es",
        "value": "En el sistema de alertas de Grafana, los usuarios con permisos de edición para un punto de contacto, específicamente los permisos 'alert.notifications:write' o 'alert.notifications.receivers:test' que se otorgan como parte del rol fijo 'Contact Point Writer', que forma parte del rol básico Editor - pueden editar puntos de contacto creados por otros usuarios, modificar la URL del endpoint a un servidor controlado. Al invocar la funcionalidad de prueba, los atacantes pueden capturar y extraer configuraciones seguras redactadas, como credenciales de autenticación para servicios de terceros (p. ej., tokens de Slack). Esto conduce a acceso no autorizado y a la posible compromiso de integraciones externas."
      }
    ],
    "id": "CVE-2025-12141",
    "lastModified": "2026-09-30T22:10:00.273",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "YES",
            "Recovery": "NOT_DEFINED",
            "Safety": "NEGLIGIBLE",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 1.3,
            "baseSeverity": "LOW",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "UNREPORTED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "LOW",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security@grafana.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-12141",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-04-15T18:45:45.527327Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-04-15T16:16:33.040",
    "references": [
      {
        "source": "security@grafana.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://grafana.com/security/security-advisories/cve-2025-12141/"
      }
    ],
    "sourceIdentifier": "security@grafana.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-200"
          }
        ],
        "source": "security@grafana.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS vector
cvss_vector
not compared
Red HatCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
receipt
Source
Red Hat
Its words
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Read by
field:cvss3_scoring_vector
Said since
2026-10-06 13:01 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
2026-10-06 13:01 UTCCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
2026-09-29 09:44 UTC—
What the source handed over
{
  "CVE": "CVE-2025-12141",
  "CWE": "CWE-266",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2458704",
  "bugzilla_description": "Grafana: Grafana: Information disclosure of secure settings via contact point modification",
  "cvss3_score": "5.0",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-04-15T14:59:41Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-12141.json",
  "severity": "low"
}
—
CWE
cwe
different words
NVDCWE-200
receipt
Source
NVD
Its words
CWE-200
Read by
field:cve.weaknesses[].description[].value
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCCWE-200
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Grafana Alerting",
            "repo": "https://github.com/grafana/grafana",
            "vendor": "Grafana",
            "versions": [
              {
                "lessThanOrEqual": "12.3.0",
                "status": "affected",
                "version": "8.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@grafana.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1DDFD2FD-7573-4993-8C82-2DBA97D95956",
                "versionEndIncluding": "12.3.0",
                "versionStartIncluding": "8.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role \"Contact Point Writer\", which is part of the basic role Editor - can edit contact points created by other users, modify the endpoint URL to a controlled server. By invoking the test functionality, attackers can capture and extract redacted secure settings, such as authentication credentials for third-party services (e.g., Slack tokens). This leads to unauthorized access and potential compromise of external integrations."
      },
      {
        "lang": "es",
        "value": "En el sistema de alertas de Grafana, los usuarios con permisos de edición para un punto de contacto, específicamente los permisos 'alert.notifications:write' o 'alert.notifications.receivers:test' que se otorgan como parte del rol fijo 'Contact Point Writer', que forma parte del rol básico Editor - pueden editar puntos de contacto creados por otros usuarios, modificar la URL del endpoint a un servidor controlado. Al invocar la funcionalidad de prueba, los atacantes pueden capturar y extraer configuraciones seguras redactadas, como credenciales de autenticación para servicios de terceros (p. ej., tokens de Slack). Esto conduce a acceso no autorizado y a la posible compromiso de integraciones externas."
      }
    ],
    "id": "CVE-2025-12141",
    "lastModified": "2026-09-30T22:10:00.273",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "YES",
            "Recovery": "NOT_DEFINED",
            "Safety": "NEGLIGIBLE",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 1.3,
            "baseSeverity": "LOW",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "UNREPORTED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "LOW",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security@grafana.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-12141",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-04-15T18:45:45.527327Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-04-15T16:16:33.040",
    "references": [
      {
        "source": "security@grafana.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://grafana.com/security/security-advisories/cve-2025-12141/"
      }
    ],
    "sourceIdentifier": "security@grafana.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-200"
          }
        ],
        "source": "security@grafana.com",
        "type": "Secondary"
      }
    ]
  }
}
—
CWE
cwe
different words
Red HatCWE-266
receipt
Source
Red Hat
Its words
CWE-266
Read by
field:CWE
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-12141",
  "CWE": "CWE-266",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2458704",
  "bugzilla_description": "Grafana: Grafana: Information disclosure of secure settings via contact point modification",
  "cvss3_score": "5.0",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-04-15T14:59:41Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-12141.json",
  "severity": "low"
}
—
Exploitation
exploitation
NVDnone
No evidence of exploitation, and no public proof of concept.
receipt
Source
NVD
Its words
none
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].exploitation
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCnone
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Grafana Alerting",
            "repo": "https://github.com/grafana/grafana",
            "vendor": "Grafana",
            "versions": [
              {
                "lessThanOrEqual": "12.3.0",
                "status": "affected",
                "version": "8.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@grafana.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1DDFD2FD-7573-4993-8C82-2DBA97D95956",
                "versionEndIncluding": "12.3.0",
                "versionStartIncluding": "8.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role \"Contact Point Writer\", which is part of the basic role Editor - can edit contact points created by other users, modify the endpoint URL to a controlled server. By invoking the test functionality, attackers can capture and extract redacted secure settings, such as authentication credentials for third-party services (e.g., Slack tokens). This leads to unauthorized access and potential compromise of external integrations."
      },
      {
        "lang": "es",
        "value": "En el sistema de alertas de Grafana, los usuarios con permisos de edición para un punto de contacto, específicamente los permisos 'alert.notifications:write' o 'alert.notifications.receivers:test' que se otorgan como parte del rol fijo 'Contact Point Writer', que forma parte del rol básico Editor - pueden editar puntos de contacto creados por otros usuarios, modificar la URL del endpoint a un servidor controlado. Al invocar la funcionalidad de prueba, los atacantes pueden capturar y extraer configuraciones seguras redactadas, como credenciales de autenticación para servicios de terceros (p. ej., tokens de Slack). Esto conduce a acceso no autorizado y a la posible compromiso de integraciones externas."
      }
    ],
    "id": "CVE-2025-12141",
    "lastModified": "2026-09-30T22:10:00.273",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "YES",
            "Recovery": "NOT_DEFINED",
            "Safety": "NEGLIGIBLE",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 1.3,
            "baseSeverity": "LOW",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "UNREPORTED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "LOW",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security@grafana.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-12141",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-04-15T18:45:45.527327Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-04-15T16:16:33.040",
    "references": [
      {
        "source": "security@grafana.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://grafana.com/security/security-advisories/cve-2025-12141/"
      }
    ],
    "sourceIdentifier": "security@grafana.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-200"
          }
        ],
        "source": "security@grafana.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Product
product
NVDGrafana Alerting
receipt
Source
NVD
Its words
Grafana Alerting
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Grafana Alerting",
            "repo": "https://github.com/grafana/grafana",
            "vendor": "Grafana",
            "versions": [
              {
                "lessThanOrEqual": "12.3.0",
                "status": "affected",
                "version": "8.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@grafana.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1DDFD2FD-7573-4993-8C82-2DBA97D95956",
                "versionEndIncluding": "12.3.0",
                "versionStartIncluding": "8.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role \"Contact Point Writer\", which is part of the basic role Editor - can edit contact points created by other users, modify the endpoint URL to a controlled server. By invoking the test functionality, attackers can capture and extract redacted secure settings, such as authentication credentials for third-party services (e.g., Slack tokens). This leads to unauthorized access and potential compromise of external integrations."
      },
      {
        "lang": "es",
        "value": "En el sistema de alertas de Grafana, los usuarios con permisos de edición para un punto de contacto, específicamente los permisos 'alert.notifications:write' o 'alert.notifications.receivers:test' que se otorgan como parte del rol fijo 'Contact Point Writer', que forma parte del rol básico Editor - pueden editar puntos de contacto creados por otros usuarios, modificar la URL del endpoint a un servidor controlado. Al invocar la funcionalidad de prueba, los atacantes pueden capturar y extraer configuraciones seguras redactadas, como credenciales de autenticación para servicios de terceros (p. ej., tokens de Slack). Esto conduce a acceso no autorizado y a la posible compromiso de integraciones externas."
      }
    ],
    "id": "CVE-2025-12141",
    "lastModified": "2026-09-30T22:10:00.273",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "YES",
            "Recovery": "NOT_DEFINED",
            "Safety": "NEGLIGIBLE",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 1.3,
            "baseSeverity": "LOW",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "UNREPORTED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "LOW",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security@grafana.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-12141",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-04-15T18:45:45.527327Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-04-15T16:16:33.040",
    "references": [
      {
        "source": "security@grafana.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://grafana.com/security/security-advisories/cve-2025-12141/"
      }
    ],
    "sourceIdentifier": "security@grafana.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-200"
          }
        ],
        "source": "security@grafana.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
conflict
NVDMEDIUM
From 4.0 to 6.9.
receipt
Source
NVD
Its words
MEDIUM
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseSeverity || field:cve.metrics.cvssMetricV31[].cvssData.baseSeverity
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCMEDIUM
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Grafana Alerting",
            "repo": "https://github.com/grafana/grafana",
            "vendor": "Grafana",
            "versions": [
              {
                "lessThanOrEqual": "12.3.0",
                "status": "affected",
                "version": "8.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@grafana.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1DDFD2FD-7573-4993-8C82-2DBA97D95956",
                "versionEndIncluding": "12.3.0",
                "versionStartIncluding": "8.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role \"Contact Point Writer\", which is part of the basic role Editor - can edit contact points created by other users, modify the endpoint URL to a controlled server. By invoking the test functionality, attackers can capture and extract redacted secure settings, such as authentication credentials for third-party services (e.g., Slack tokens). This leads to unauthorized access and potential compromise of external integrations."
      },
      {
        "lang": "es",
        "value": "En el sistema de alertas de Grafana, los usuarios con permisos de edición para un punto de contacto, específicamente los permisos 'alert.notifications:write' o 'alert.notifications.receivers:test' que se otorgan como parte del rol fijo 'Contact Point Writer', que forma parte del rol básico Editor - pueden editar puntos de contacto creados por otros usuarios, modificar la URL del endpoint a un servidor controlado. Al invocar la funcionalidad de prueba, los atacantes pueden capturar y extraer configuraciones seguras redactadas, como credenciales de autenticación para servicios de terceros (p. ej., tokens de Slack). Esto conduce a acceso no autorizado y a la posible compromiso de integraciones externas."
      }
    ],
    "id": "CVE-2025-12141",
    "lastModified": "2026-09-30T22:10:00.273",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "YES",
            "Recovery": "NOT_DEFINED",
            "Safety": "NEGLIGIBLE",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 1.3,
            "baseSeverity": "LOW",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "UNREPORTED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "LOW",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security@grafana.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-12141",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-04-15T18:45:45.527327Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-04-15T16:16:33.040",
    "references": [
      {
        "source": "security@grafana.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://grafana.com/security/security-advisories/cve-2025-12141/"
      }
    ],
    "sourceIdentifier": "security@grafana.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-200"
          }
        ],
        "source": "security@grafana.com",
        "type": "Secondary"
      }
    ]
  }
}
medium
Severity
severity
conflict
Red Hatlow
A flaw that is unlikely to be exploited, or whose impact is minimal.
receipt
Source
Red Hat
Its words
low
Read by
field:severity
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2025-12141",
  "CWE": "CWE-266",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2458704",
  "bugzilla_description": "Grafana: Grafana: Information disclosure of secure settings via contact point modification",
  "cvss3_score": "5.0",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-04-15T14:59:41Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-12141.json",
  "severity": "low"
}
—
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Grafana Alerting",
            "repo": "https://github.com/grafana/grafana",
            "vendor": "Grafana",
            "versions": [
              {
                "lessThanOrEqual": "12.3.0",
                "status": "affected",
                "version": "8.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@grafana.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1DDFD2FD-7573-4993-8C82-2DBA97D95956",
                "versionEndIncluding": "12.3.0",
                "versionStartIncluding": "8.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role \"Contact Point Writer\", which is part of the basic role Editor - can edit contact points created by other users, modify the endpoint URL to a controlled server. By invoking the test functionality, attackers can capture and extract redacted secure settings, such as authentication credentials for third-party services (e.g., Slack tokens). This leads to unauthorized access and potential compromise of external integrations."
      },
      {
        "lang": "es",
        "value": "En el sistema de alertas de Grafana, los usuarios con permisos de edición para un punto de contacto, específicamente los permisos 'alert.notifications:write' o 'alert.notifications.receivers:test' que se otorgan como parte del rol fijo 'Contact Point Writer', que forma parte del rol básico Editor - pueden editar puntos de contacto creados por otros usuarios, modificar la URL del endpoint a un servidor controlado. Al invocar la funcionalidad de prueba, los atacantes pueden capturar y extraer configuraciones seguras redactadas, como credenciales de autenticación para servicios de terceros (p. ej., tokens de Slack). Esto conduce a acceso no autorizado y a la posible compromiso de integraciones externas."
      }
    ],
    "id": "CVE-2025-12141",
    "lastModified": "2026-09-30T22:10:00.273",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "YES",
            "Recovery": "NOT_DEFINED",
            "Safety": "NEGLIGIBLE",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 1.3,
            "baseSeverity": "LOW",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "UNREPORTED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "LOW",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security@grafana.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-12141",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-04-15T18:45:45.527327Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-04-15T16:16:33.040",
    "references": [
      {
        "source": "security@grafana.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://grafana.com/security/security-advisories/cve-2025-12141/"
      }
    ],
    "sourceIdentifier": "security@grafana.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-200"
          }
        ],
        "source": "security@grafana.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Technical impact
technical_impact
NVDpartial
The attacker gains limited control, or limited information.
receipt
Source
NVD
Its words
partial
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].technicalImpact
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCpartial
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Grafana Alerting",
            "repo": "https://github.com/grafana/grafana",
            "vendor": "Grafana",
            "versions": [
              {
                "lessThanOrEqual": "12.3.0",
                "status": "affected",
                "version": "8.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@grafana.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1DDFD2FD-7573-4993-8C82-2DBA97D95956",
                "versionEndIncluding": "12.3.0",
                "versionStartIncluding": "8.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role \"Contact Point Writer\", which is part of the basic role Editor - can edit contact points created by other users, modify the endpoint URL to a controlled server. By invoking the test functionality, attackers can capture and extract redacted secure settings, such as authentication credentials for third-party services (e.g., Slack tokens). This leads to unauthorized access and potential compromise of external integrations."
      },
      {
        "lang": "es",
        "value": "En el sistema de alertas de Grafana, los usuarios con permisos de edición para un punto de contacto, específicamente los permisos 'alert.notifications:write' o 'alert.notifications.receivers:test' que se otorgan como parte del rol fijo 'Contact Point Writer', que forma parte del rol básico Editor - pueden editar puntos de contacto creados por otros usuarios, modificar la URL del endpoint a un servidor controlado. Al invocar la funcionalidad de prueba, los atacantes pueden capturar y extraer configuraciones seguras redactadas, como credenciales de autenticación para servicios de terceros (p. ej., tokens de Slack). Esto conduce a acceso no autorizado y a la posible compromiso de integraciones externas."
      }
    ],
    "id": "CVE-2025-12141",
    "lastModified": "2026-09-30T22:10:00.273",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "YES",
            "Recovery": "NOT_DEFINED",
            "Safety": "NEGLIGIBLE",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 1.3,
            "baseSeverity": "LOW",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "UNREPORTED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "LOW",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security@grafana.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-12141",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-04-15T18:45:45.527327Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-04-15T16:16:33.040",
    "references": [
      {
        "source": "security@grafana.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://grafana.com/security/security-advisories/cve-2025-12141/"
      }
    ],
    "sourceIdentifier": "security@grafana.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-200"
          }
        ],
        "source": "security@grafana.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDGrafana
receipt
Source
NVD
Its words
Grafana
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Grafana Alerting",
            "repo": "https://github.com/grafana/grafana",
            "vendor": "Grafana",
            "versions": [
              {
                "lessThanOrEqual": "12.3.0",
                "status": "affected",
                "version": "8.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@grafana.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "1DDFD2FD-7573-4993-8C82-2DBA97D95956",
                "versionEndIncluding": "12.3.0",
                "versionStartIncluding": "8.0.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role \"Contact Point Writer\", which is part of the basic role Editor - can edit contact points created by other users, modify the endpoint URL to a controlled server. By invoking the test functionality, attackers can capture and extract redacted secure settings, such as authentication credentials for third-party services (e.g., Slack tokens). This leads to unauthorized access and potential compromise of external integrations."
      },
      {
        "lang": "es",
        "value": "En el sistema de alertas de Grafana, los usuarios con permisos de edición para un punto de contacto, específicamente los permisos 'alert.notifications:write' o 'alert.notifications.receivers:test' que se otorgan como parte del rol fijo 'Contact Point Writer', que forma parte del rol básico Editor - pueden editar puntos de contacto creados por otros usuarios, modificar la URL del endpoint a un servidor controlado. Al invocar la funcionalidad de prueba, los atacantes pueden capturar y extraer configuraciones seguras redactadas, como credenciales de autenticación para servicios de terceros (p. ej., tokens de Slack). Esto conduce a acceso no autorizado y a la posible compromiso de integraciones externas."
      }
    ],
    "id": "CVE-2025-12141",
    "lastModified": "2026-09-30T22:10:00.273",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.8,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "YES",
            "Recovery": "NOT_DEFINED",
            "Safety": "NEGLIGIBLE",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 1.3,
            "baseSeverity": "LOW",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "UNREPORTED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "LOW",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "LOW",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "security@grafana.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-12141",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-04-15T18:45:45.527327Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-04-15T16:16:33.040",
    "references": [
      {
        "source": "security@grafana.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://grafana.com/security/security-advisories/cve-2025-12141/"
      }
    ],
    "sourceIdentifier": "security@grafana.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-200"
          }
        ],
        "source": "security@grafana.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Every claim, by kind

vulnerability

Grafana: Grafana: Information disclosure of secure settings via contact point modification
zetlyn/cve-redhat · 2026-04-15
cvss 5 cvss_vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N cwe CWE-266 severity low source
In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role "Contact Point Writer", which is part of the basic role Editor - can edit contact points created by other users, modify the endpoint URL to a controlled server. By invoking the test functionality, attackers can capture and extract redacted secure settings, such as authentication credentials for third-party services (e.g., Slack tokens). This leads to unauthorized access and potential compromise of external integrations.
zetlyn/cve-nvd · 2026-04-15
automatable yes cvss 6.5 cvss4 1.3 cvss4_vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:X/RE:X/U:X cvss_vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N cwe CWE-200 exploitation none product Grafana Alerting severity MEDIUM status Analyzed technical_impact partial vendor Grafana source