{"id":"GHSA-fcw4-wwqm-m8cf","summary":"Grafana Operator: Privilege escalation from namespace admin to cluster admin via GrafanaDashboard jsonnetLib fileName","details":"We have released version 5.24.0 of the Grafana Operator. This patch includes a MODERATE severity security fix for a path traversal/privilege escalation vulnerability in the Grafana Operator.\n\n\n### Summary\n\nThe Grafana Operator supports loading dashboards & library panels using the jsonnet data templating language. The jsonnet expression is evaluated in the context of the operator manager pod.\n### Impact\n\nIt is possible for a malicious user who can create `Dashboard` or `LibraryPanel` resources for a `Grafana` instance to obtain the Kubernetes service account token of the Grafana Operator manager.\n\n### Affected versions\n\nAll Grafana Operator versions \u003c= 5.23\n\n### Solutions and mitigations\n\nAll installations should be upgraded as soon as possible.\n\nAs a workaround, the following ValidatingAdmissionPolicy prevent the creation or modification of jsonnet based resources:\n```\napiVersion: admissionregistration.k8s.io/v1\nkind: ValidatingAdmissionPolicy\nmetadata:\n  name: \"prevent-jsonnet-dashboards\"\nspec:\n  failurePolicy: Fail\n  matchConstraints:\n    resourceRules:\n      - apiGroups: [\"grafana.integreatly.org\"]\n        apiVersions: [\"v1beta1\"]\n        operations: [\"CREATE\", \"UPDATE\"]\n        resources: [\"grafanadashboards\", \"grafanalibrarypanels\"]\n  validations:\n    - expression: \"!has(object.spec.jsonnetLib)\"\n---\napiVersion: admissionregistration.k8s.io/v1\nkind: ValidatingAdmissionPolicyBinding\nmetadata:\n  name: \"prevent-jsonnet-dashboards-clusterwide\"\nspec:\n  policyName: \"prevent-jsonnet-dashboards\"\n  validationActions: [Deny]\n```\n\n\n### Acknowledgement\n\nWe would like to thank [Artem Cherezov](https://github.com/cherez0ff) for responsibly disclosing the vulnerability.","aliases":["CVE-2026-11769","GO-2026-5355"],"modified":"2026-06-25T19:56:37.002106882Z","published":"2026-06-19T20:51:16Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-200","CWE-22"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-06-19T20:51:16Z"},"references":[{"type":"WEB","url":"https://github.com/grafana/grafana-operator/security/advisories/GHSA-fcw4-wwqm-m8cf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-11769"},{"type":"PACKAGE","url":"https://github.com/grafana/grafana-operator"},{"type":"WEB","url":"https://grafana.com/security/security-advisories/cve-2026-11769"}],"affected":[{"package":{"name":"github.com/grafana/grafana-operator/v5","ecosystem":"Go","purl":"pkg:golang/github.com/grafana/grafana-operator/v5"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"5.24.0"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 5.23.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-fcw4-wwqm-m8cf/GHSA-fcw4-wwqm-m8cf.json"}},{"package":{"name":"github.com/grafana/grafana-operator","ecosystem":"Go","purl":"pkg:golang/github.com/grafana/grafana-operator"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"2.0.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-fcw4-wwqm-m8cf/GHSA-fcw4-wwqm-m8cf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N"}]}