CVE-2026-42129Disclosed before NVD

Path traversal in the Loki data source leads to internal information disclosure

Published
June 9, 2026
Last Modified

📋 Description

A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information. Upgrade to a fixed version listed below.

🎯 Affected products1

  • Loki

🔗 References (1)