CVE-2026-42129

The Loki datasource plugin's callResource handler contains a path traversal vulnerability. An authenticated Viewer-role user can escape the plugin's resource sandbox and access administrative Loki endpoints (e.g. /config, /services, /ready) to extract sensitive backend configuration and internal service information.
Configurations

No configuration.

History

24 Jun 2026, 17:17

Type Values Removed Values Added
CWE CWE-22

22 Jun 2026, 14:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-22 14:17

Updated : 2026-06-24 17:17


NVD link : CVE-2026-42129

Mitre link : CVE-2026-42129

CVE.ORG link : CVE-2026-42129


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')