CVE-2026-17033
Last modified
CVE-2026-17033 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. An authenticated attacker with Editor access or alert.instances.external:write can submit an external Alertmanager alert containing a controlled generatorURL. The attacker is authorized to create the alert, but not to execute script in another user's Grafana session. Grafana renders alert.generatorURL directly as the Alert Details See source LinkButton href without URL-scheme sanitization or a safe-protocol allowlist. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
An authenticated attacker with Editor access or alert.instances.external:write can submit an external Alertmanager alert containing a controlled generatorURL. The attacker is authorized to create the alert, but not to execute script in another user's Grafana session. Grafana renders alert.generatorURL directly as the Alert Details See source LinkButton href without URL-scheme sanitization or a safe-protocol allowlist. The click interceptor's :// heuristic can be bypassed by placing :// inside a JavaScript comment. When a user with read access clicks See source, the browser executes attacker-controlled JavaScript in the Grafana origin with the clicking user's permissions.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Grafana | Grafana OSS | <= 12.3.11; >= 12.4.0, <= 12.4.9; >= 13.0.0, <= 13.0.7 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-17033?
How severe is CVE-2026-17033?
How do I fix CVE-2026-17033?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-17023The Salon Booking System WordPress plugin through 10.30.33 …4.8
- CVE-2026-17024IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a …9.8
- CVE-2026-17028IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.3…6.5
- CVE-2026-17029IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to…8.8
- CVE-2026-1703When pip is installing and extracting a maliciously crafted …2
- CVE-2026-17032Multiple Supsystic Pro plugins were distributed with malicio…9.8
- CVE-2026-17037The Kirki – Freeform Page Builder, Website Builder & Customi…7.2
- CVE-2026-17038DrEryk Gabinet before 11.5.0 uses hard-coded API credentials…6.9
- CVE-2026-17039A flaw was found in pki-core. The certificate authority (CA)…3.1
- CVE-2026-1704The Appointment Booking Calendar — Simply Schedule Appointme…4.3
- CVE-2026-17040IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a …9.8
- CVE-2026-17042IBM Power Systems Firmware FW950.00 through FW950.H2, OP940.…7.3
Are you affected by CVE-2026-17033?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
