RHSA-2026:68821HighCVSS 7.5

Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update

Published
September 18, 2026
Last Modified
October 2, 2026

🔗 CVE IDs covered (14)

📋 Description

CVE-2026-28374 — grafana: Grafana: Unauthorized annotation deletion by editor users CVE-2026-28376 — grafana: Grafana Live: Denial of Service due to unbounded memory allocation via push endpoint CVE-2026-28379 — grafana: Grafana Live: Denial of Service due to a race condition CVE-2026-28380 — grafana: Grafana: Unauthorized snapshot deletion via Broken Access Control in Snapshot API CVE-2026-28383 — grafana: Grafana: Denial of Service via unbounded memory allocation in plugin resources endpoint CVE-2026-33376 — grafana: Grafana Auth Proxy: Unauthorized access due to incorrect IPv6 allow-list default CVE-2026-33377 — grafana: Grafana: Privilege escalation via dashboard overwrite CVE-2026-33378 — grafana: Grafana: Denial of Service due to Out of Memory via $__timeGroup macro CVE-2026-33380 — grafana: Grafana: Information disclosure via SQL Expressions vulnerability CVE-2026-33381 — grafana: Grafana: Temporary access control bypass for service account token minting CVE-2026-61709 — github.com/openfga/openfga: OpenFGA: Unauthorized access due to ListUsers API returning deliberately excluded users. CVE-2026-81871 — go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc: OpenTelemetry-Go: TLS certificate bypass allows log telemetry interception and alteration CVE-2026-81872 — go.opentelemetry.io/otel/sdk/log: OpenTelemetry-Go: Denial of Service via attacker-driven log emission CVE-2026-92599 — joi: joi: Denial of Service via isoDate validation regular expression

🎯 Affected products4

  • Red Hat Hardened Images
  • grafana12.4-0:12.4.10-0.6.hum1@aarch64 as a component of Red Hat Hardened Images
  • grafana12.4-0:12.4.10-0.6.hum1@src as a component of Red Hat Hardened Images
  • grafana12.4-0:12.4.10-0.6.hum1@x86_64 as a component of Red Hat Hardened Images

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, explicitly specify the intended IPv6 address mask—typically /128 for a single host—within the Grafana Auth Proxy allow-list configuration. This overrides the incorrect default /32 mask, ensuring that network access restrictions are applied strictly as intended. For RHEL: Update the whitelist directive under the [auth.proxy] section in /etc/grafana/grafana.ini. For example, if ::1 is the desired address, configure it explicitly as ::1/128. A restart of the Grafana service (systemctl restart grafana-server) is required for the changes to take effect. Workaround: Audit dashboard-level permissions to ensure that write access is granted only to users who should be able to modify each specific dashboard. Revoke per-dashboard write permissions from Editor users who do not strictly require them. Workaround: No product-side mitigation is required while Zanzana remains disabled, which is the default. If Zanzana has been turned on, do not use ListUsers results as an access-control decision; use Check for each user and object until Grafana vendors OpenFGA 1.18.1 or later. Workaround: To mitigate this vulnerability, ensure that any input strings processed by the `Joi.string().isoDate()` validation rule are capped in length before being passed to the 'joi' package. This can prevent the regular expression engine from consuming excessive resources and causing a denial of service.

🔗 References (18)