CVE-2026-63087: Grafana OnCall 1.16.11 Unauthenticated Token Hijack via Plugin Install Endpoint
Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the internal plugin install endpoint using hardcoded default stackid and orgid values present in the public source tree. Attackers can leverage the acquired token to authenticate against all internal API endpoints, create arbitrary Admin users via the user-context header bootstrap path, revoke the legitimate plugin token, and redirect OnCall-to-Grafana API calls to an attacker-controlled host by overwriting the organization's grafanaurl and apitoken.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Grafana OnCallto a version that resolves this vulnerability.Fixed in 1.16.11 - Upgrade
Upgrade
Grafana OnCallto a version that resolves this vulnerability.Fixed in 1.16.11Patch Unauthenticated Token Hijack via Plugin Install Endpoint
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63087?
CVE-2026-63087 has a critical severity rating of 9.8.
How do I fix CVE-2026-63087?
To mitigate CVE-2026-63087, update Grafana OnCall to version 1.16.12 or later.
What does CVE-2026-63087 allow attackers to do?
CVE-2026-63087 allows attackers to hijack a valid PluginAuthToken via an unauthenticated request to the plugin install endpoint.
Which versions of Grafana OnCall are affected by CVE-2026-63087?
CVE-2026-63087 affects Grafana OnCall versions up to and including 1.16.11.
Is authentication required to exploit CVE-2026-63087?
No, CVE-2026-63087 can be exploited without authentication.