Skip to content

Grafana Remote Arbitrary Code Execution Vulnerability (CVE-2026-27876) #270

@hildebrau

Description

@hildebrau

You may want to update docker-compose.yml due to this Grafana related CVE:
Grafana Remote Arbitrary Code Execution Vulnerability (CVE-2026-27876)

Grafana has released a patch addressing the issue. For more information, please refer to  Grafana Security Advisory (https://grafana.com/security/security-advisories/cve-2026-27876/) Patch: Following are links for downloading patches to fix the vulnerabilities:   Grafana Downloads (https://grafana.com/grafana/download)

Why is docker-compose pinned to certain builds?
FYI, for fun, I set them all to the :latest tags, and Prometheus wasn't happy.. no new data came in, so I rolled that one back to v2.53.5 and data started flowing again. But the good news is Grafana 12.4.2 seems to work enough to show me a graph of F5 AST data.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions