Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-21726

19
FAUCET Score

BRIEFING NOTE - CVE SUMMARY This vulnerability affects the Ruler API and represents a path traversal weakness in the /loki/api/v1/rules/{namespace} endpoint. The CVE-2021-36156 fix that validated the namespace parameter for malicious sequences was bypassed through double URL encoding, allowing attackers to circumvent the security control and read arbitrary files from the system. The vulnerability carries a CVSS 3.1 score of 5.3 (Medium severity) with a network-based attack vector requiring no authentication or user interaction. The attack complexity is low, and the primary impact is confidentiality loss through unauthorized file access, with no direct impact to system integrity or availability. The FAUCET risk score of 32.0 out of 100 indicates a moderate overall threat level. Exploitation status shows no current active exploitation in the wild, as indicated by the inactive Hot List status and no Known Exploited Vulnerabilities designation. The EPSS probability of exploitation is extremely low at 0.00015. Community attention appears limited given the minimal prevalence metrics, suggesting this remains a lower-priority item for immediate patching compared to more widely exploited vulnerabilities, though affected organizations should still apply fixes as part of regular maintenance cycles.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.6.4CPE matchmatch criteria
cpe:2.3:a:grafana:loki:*:*:*:*:*:*:*:*
>= 2.3.0, < 3.5.9CPE match
cpe:2.3:a:grafana:loki:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.41%
Probability of exploitation in next 30 days
EPSS Percentile
33.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0041 is in the 21st percentile among its peer group of 23,725 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

gopatch availablevia ghsa
Product: github.com/grafana/loki/v3Fixed in: 3.6.4

Vendor Advisories (1)

goGHSA-497x-rrr9-68jpmedium

Grafana Loki Path Traversal - CVE-2021-36156 Bypass

Apr 15, 2026

References

grafana.com / security/security-advisories/cve-2026-21726
Vendor Advisory