CVE-2026-22642: Medium severity grafana/grafana vulnerability
Published Jan 15, 2026
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected Software
1 affected component
grafana/grafana
Remediation
Information
Users are strongly recommended to upgrade to the latest release of Incoming Goods Suite (>= 1.2.1).
Event History
Jan 15, 2026
CVE Published
via MITRE·01:13 PM
Rejected
via MITRE·01:13 PM
Data Sourced
via NVD·02:16 PM
Description
Jan 22, 2026
Rejected
via MITRE·05:06 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-22642?
CVE-2026-22642 is classified as a medium severity open redirect vulnerability.
2
How does CVE-2026-22642 affect Grafana OSS?
CVE-2026-22642 allows an attacker to redirect users to malicious sites by exploiting the organization switching feature.
3
What are the prerequisites for exploiting CVE-2026-22642?
To exploit CVE-2026-22642, multiple organizations must exist in the Grafana instance, and the victim must belong to a different organization than the one specified in the URL.
4
How can I mitigate CVE-2026-22642?
Mitigation for CVE-2026-22642 includes validating and sanitizing user input URLs to prevent unauthorized redirects.
5
What should I do if I am affected by CVE-2026-22642?
If affected by CVE-2026-22642, update your Grafana OSS to the latest version that addresses this vulnerability.