What is CVE-2026-21723?
CVE-2026-21723 allows the Alertmanager templates test endpoint in Grafana to execute templates without memory limits, causing OOM and crashing the service through mass template execution. The endpoint is exploitable with very low privileges, including anonymous access, making it critical to upgrade Grafana or restrict network access to mitigate the risk.
Azərbaycanca: CVE-2026-21723 Grafana-da Alertmanager şablon test endpoint-inin (/api/alertmanager/grafana/config/api/v1/templates/test) yaddaş limiti olmadan şablonları icra etməsi səbəbindən OOM (Out of Memory) vəziyyəti yaradaraq xidməti çökdürür. Zəiflik çox aşağı səlahiyyətlərlə, hətta anonim istifadəçilər tərəfindən istismar edilə bilər. Bu problemi aradan qaldırmaq üçün dərhal Grafana-nı ən son versiyaya yeniləmək və ya şəbəkə səviyyəsində giriş məhdudiyyətləri tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
What functionality in Grafana is affected by CVE-2026-21723?
It affects the Alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test).
What are the primary mitigations for CVE-2026-21723?
It is recommended to immediately upgrade Grafana to the latest version or apply network-level access restrictions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.