EUVD-2026-38241
A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Not present in the current ENISA EUVD known-exploited dataset. This is not proof of no exploitation.
- ENISA score
- 7.7 · CVSS 3.1
- Advisory evidence
- No linked advisory details stored yet
