Die aktuelle Version von Grafana ist 13.2.3 (Stand 29.09.2026). patchletter prüft die offizielle Quelle täglich und mailt dir neue Releases.
Aktiv ausgenutzte Schwachstellen
Die US-Cybersicherheitsbehörde CISA führt diese Schwachstellen in ihrem Katalog bekannter, aktiv ausgenutzter Lücken (Known Exploited Vulnerabilities). Was CISA nicht führt, steht nicht in dieser Liste — auch wenn es ausgenutzt wird.
- CVE-2021-43798Grafana Path Traversal Vulnerability
7.5 hoch · aus dem Netz, ohne Anmeldung · CISA-Frist war 30. Okt. 25
- CVE-2021-39226Grafana Authentication Bypass Vulnerability
7.3 hoch · aus dem Netz, ohne Anmeldung · CISA-Frist war 15. Sept. 22
Quelle: CISA KEV. Der CVE-Bezug wird automatisch dem Produkt zugeordnet — im Zweifel gilt der verlinkte NVD-Eintrag.
BSI-Sicherheitshinweise
Meldungen, die das BSI (CERT-Bund) zu diesem Produkt veröffentlicht hat. Ob deine Version betroffen ist, steht in der Meldung selbst.
- Grafana: Mehrere Schwachstellen
WID-SEC-W-2026-1546 · 7. Okt.
- Grafana: Schwachstelle ermöglicht Cross-Site Scripting
WID-SEC-W-2026-3474 · 6. Okt.
- Grafana: Mehrere Schwachstellen
WID-SEC-W-2026-3675 · 6. Okt.
- Grafana: Schwachstelle ermöglicht Offenlegung von Informationen
WID-SEC-W-2026-3652 · 6. Okt.
- Grafana: Schwachstelle ermöglicht Codeausführung
WID-SEC-W-2026-3450 · 18. Sept.
- Grafana: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen und Offenlegung von Informationen
WID-SEC-W-2026-3355 · 15. Sept.
- Grafana: Mehrere Schwachstellen
WID-SEC-W-2026-2289 · 15. Sept.
- Grafana: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen und Manipulation von Dateien
WID-SEC-W-2026-3039 · 10. Sept.
Grafana im Überblick
Grafana ist das Standard-Frontend fürs Monitoring — Dashboards über Prometheus, Loki, InfluxDB und Dutzende weitere Quellen. Das Projekt veröffentlicht mehrere Minor-Versionen pro Jahr plus häufige Patch-Releases; Sicherheitsupdates erscheinen regelmäßig und betreffen nicht selten die Authentifizierungs- oder Datasource-Ebene.
Da Grafana oft von außen erreichbar ist (und Zugangsdaten zu Datenquellen hält), gehören Security-Releases zügig eingespielt. Der Betrieb hinter einem Auth-Proxy/SSO reduziert die Angriffsfläche zusätzlich.
Updates innerhalb einer Major-Version sind meist unaufgeregt; bei Major-Sprüngen wollen Plugins (Panel/Datasource), Provisioning-Dateien und Alerting-Migrationen geprüft werden — insbesondere ältere Angular-basierte Plugins sind ein wiederkehrendes Auslauf-Thema. Dashboards als Code (Provisioning/Git) macht Rollbacks entspannt.
Dashboards für alles.
Support-Zyklen (endoflife.date)
| Zyklus | Neueste Version | Status |
|---|---|---|
| 13.2 | 13.2.3 | EOL 18. Mai 27 |
| 13.1 | 13.1.7 | EOL 20. März 27 |
| 13.0 | 13.0.10 | EOL 9. Jan. 27 |
| 12.4 | 12.4.12 | EOL 24. Mai 27 |
| 12.3 | 12.3.11 | End of Life |
| 12.2 | 12.2.10 | End of Life |
| 12.1 | 12.1.10+security-01 | End of Life |
| 12.0 | 12.0.10 | End of Life |
Versionshistorie & Changelog · wie von patchletter erkannt
| Version | Channel | Datum | Notes |
|---|---|---|---|
| 13.2.3 | STABLE | 29.09.2026 | Release Notes → |
| 13.2.2 | STABLE | 15.09.2026 | – |
| 13.2.1 | STABLE | 01.09.2026 | – |
| 13.2.0 | STABLE | 18.08.2026 | Release Notes → |
| 13.1.4 | STABLE | 18.08.2026 | – |
| 13.1.3 | STABLE | 07.08.2026 | Release Notes → |
| 13.1.2 | STABLE | 04.08.2026 | – |
| 13.1.1 | STABLE | 21.07.2026 | Release Notes → |
| 13.1.0 | STABLE | 01.07.2026 | Release Notes → |
| 13.0.4 | STABLE | 21.07.2026 | Release Notes → |
| 13.0.3 | STABLE | 23.06.2026 | Release Notes → |
| 13.0.2 | STABLE | 09.06.2026 | Release Notes → |
| 13.0.1 | STABLE | 17.04.2026 | Release Notes → |
| 13.0.1+security-01 | STABLE | 12.05.2026 | Release Notes → |
| 12.4.6 | STABLE | 21.07.2026 | Release Notes → |
| 12.4.5 | STABLE | 23.06.2026 | Release Notes → |
| 12.4.4 | STABLE | 09.06.2026 | Release Notes → |
| 12.4.3 | STABLE | 14.04.2026 | Release Notes → |
| 12.4.3+security-02 | STABLE | 12.05.2026 | Release Notes → |
| 12.4.2 | STABLE | 25.03.2026 | Release Notes → |
| 12.4.1 | STABLE | 09.03.2026 | Release Notes → |
| 12.4.0 | STABLE | 25.02.2026 | Release Notes → |
| 12.3.9 | STABLE | 21.07.2026 | Release Notes → |
| 12.3.8 | STABLE | 23.06.2026 | Release Notes → |
| 12.3.7 | STABLE | 09.06.2026 | Release Notes → |
| 12.3.6 | STABLE | 26.03.2026 | Release Notes → |
| 12.3.6+security-04 | STABLE | 12.05.2026 | Release Notes → |
| 12.3.6+security-01 | STABLE | 26.03.2026 | Release Notes → |
| 12.3.5 | STABLE | 09.03.2026 | Release Notes → |
| 12.3.4 | STABLE | 24.02.2026 | Release Notes → |
| 12.3.3 | STABLE | 12.02.2026 | Release Notes → |
| 12.3.2 | STABLE | 27.01.2026 | Release Notes → |
| 12.3.2+security-01 | STABLE | 11.02.2026 | Release Notes → |
| 12.3.1 | STABLE | 16.12.2025 | Release Notes → |
| 12.3.0 | STABLE | 19.11.2025 | Release Notes → |
| 12.2.10 | STABLE | 23.06.2026 | Release Notes → |
| 12.2.9 | STABLE | 09.06.2026 | Release Notes → |
| 12.2.8 | STABLE | 26.03.2026 | Release Notes → |
| 12.2.8+security-04 | STABLE | 12.05.2026 | Release Notes → |
| 12.2.8+security-01 | STABLE | 25.03.2026 | Release Notes → |
| 12.2.7 | STABLE | 09.03.2026 | Release Notes → |
| 12.2.6 | STABLE | 24.02.2026 | Release Notes → |
| 12.2.5 | STABLE | 12.02.2026 | Release Notes → |
| 12.2.4 | STABLE | 27.01.2026 | Release Notes → |
| 12.2.4+security-01 | STABLE | 11.02.2026 | Release Notes → |
| 12.2.3 | STABLE | 16.12.2025 | Release Notes → |
| 12.2.2 | STABLE | 19.11.2025 | Release Notes → |
| 12.2.1 | STABLE | 21.10.2025 | Release Notes → |
| 12.2.1+security-01 | STABLE | 19.11.2025 | Release Notes → |
| 12.2.0 | STABLE | 24.09.2025 | Release Notes → |
Häufige Fragen
- Was ist die aktuelle Version von Grafana?
- Grafana 13.2.3, veröffentlicht am 29.09.2026. patchletter prüft die offizielle Quelle des Herstellers täglich auf neue Releases.
- Wo finde ich die Release Notes zu Grafana?
- Die Versionshistorie oben verlinkt die offiziellen Release Notes des Herstellers, soweit er sie veröffentlicht. patchletter speichert bewusst keine Vendor-Volltexte.
- Wie erfahre ich von neuen Grafana-Updates?
- Hak Grafana im Katalog an und hinterleg deine Adresse. Von da an gehen neue Versionen als Mail raus — einzeln oder gebündelt im Tages- oder Wochen-Digest.
Eine Mail, sobald es eine neue Grafana-Version gibt
Täglich gleichen wir die Herstellerquelle ab. Erscheint eine neue Version, liegt sie sofort oder gebündelt als Digest im Postfach. Die Update-Mail ist kostenlos und endet mit einem Klick. Warnungen zu Sicherheitslücken und zum Support-Ende gehören zu patchletter Pro.
Badge einbetten
Das Badge zeigt die aktuelle Grafana-Version und hält sie aktuell. Einbinden darf es jeder, ohne Konto.
[](https://patchletter.com/de/software/grafana)https://patchletter.com/badge/grafana.svgAuch verfügbar: ?v=eol (Support-Ende) und ?v=cve (aktiv ausgenutzt).