SUSE-SU-2026:1037-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20261037-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1037-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:1037-1
Upstream
CVE (5)
Related
Published
2026-03-25T10:31:04Z
Modified
2026-03-26T09:00:55Z
Summary
Security update for grafana
Details

This update for grafana fixes the following issues:

  • Security issues fixed:

    • CVE-2026-21722: Public dashboards annotations: use dashboard timerange if time selection disabled (bsc#1258136)
    • CVE-2026-21721: Fixed access control by the dashboard permissions API (bsc#1257337)
    • CVE-2026-21720: Fixed unauthenticated DoS (bsc#1257349)
    • CVE-2025-68156: Fixed potential DoS via unbounded recursion in builtin functions (bsc#1255340)
    • CVE-2025-3415: Fixed exposure of DingDing alerting integration URL to Viewer level users (bsc#1245302)
  • Version update from 11.5.10 to 11.6.11 with the following highlighted changes and fixes:

    • Performance Boost: Introduced WebGL-powered geomaps for smoother map visualizations and removed blurred backgrounds from UI overlays to speed up the interface.
    • One-Click Actions: Visualizations now support faster navigation via one-click links and actions.
    • Alerting History: Added version history for alert rules, allowing you to track changes over time.
    • Service Accounts: Automated the migration of old API keys to more secure Service Accounts upon startup.
    • Cron Support: Annotations now support Cron syntax for more flexible scheduling.
    • Identity and Auth: Hardened the Avatar feature (now requires sign-in) and fixed several login redirection issues when Grafana is hosted on a subpath.
    • Data Source Support: Added support for Cloud Partner Prometheus data sources and improved Azure legend formatting.
    • Alerting Limits: Added size limits for expanded notification templates to prevent system strain.
    • RBAC: Integrated Role-Based Access Control (RBAC) into the Alertmanager via the reqAction field.
    • Data Consistency: Fixed several issues with Graphite and InfluxDB regarding how variables are handled in repeated rows or nested queries.
    • Dashboard Reliability: Resolved bugs involving row repeats and 'self-referencing' data links.
    • Alerting Fixes: Patched a critical 'panic' (crash) caused by a race condition in alert rules and fixed issues where contact points weren't working correctly.
    • URL Handling: Fixed a bug where 'true' values in URL parameters weren't being read correctly
References

Affected packages

SUSE:Linux Enterprise Module for Package Hub 15 SP7 / grafana

Package

Name
grafana
Purl
pkg:rpm/suse/grafana&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
11.6.11-150200.3.83.1

Ecosystem specific

{
    "binaries":  [
        {
            "grafana":  "11.6.11-150200.3.83.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1037-1.json"

openSUSE:Leap 15.6 / grafana

Package

Name
grafana
Purl
pkg:rpm/opensuse/grafana&distro=openSUSE%20Leap%2015.6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
11.6.11-150200.3.83.1

Ecosystem specific

{
    "binaries":  [
        {
            "grafana":  "11.6.11-150200.3.83.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1037-1.json"