Is Grafana 12.3.8 patched?
Current stable (13.1.0): 100/100
12.3.8 has 2 open critical-or-high vulnerabilities. Run 12.4.4 or later to clear them. See what 12.4.4 fixes →
Summary iPlain-English security status for Grafana 12.3.8, built from its CVEs, active-exploitation data, end-of-life date and latest release.
Grafana 12.3.8 is part of the 12.3 release line. 3 known vulnerabilities affect it. The minimum safe version is 12.4.4 — upgrade to it or later to clear the open critical/high issues. The 12.3 line is supported until 2026-08-19. The latest supported Grafana release is 13.1.0.
Known issues affecting 12.3.8
Exploited first, then by exploitation probability.
CVE-2026-27876 CRITICAL EPSS 2% → fixed in 12.4.0 CVE-2026-27880 HIGH EPSS 1% → fixed in 12.4.0 CVE-2026-27877 MEDIUM EPSS 0% → fixed in 12.4.0Other Grafana versions
Check another release line of Grafana.
Frequently asked
Is Grafana 12.3.8 patched?
Grafana 12.3.8 has 2 open critical-or-high vulnerabilities. The minimum safe version is 12.4.4 — upgrade to 12.4.4 or later to clear them.
What version should I upgrade Grafana 12.3.8 to?
Upgrade Grafana 12.3.8 to at least 12.4.4 to clear its 2 open critical-or-high vulnerabilities.
When does Grafana 12.3 reach end-of-life?
Grafana 12.3 is supported until 2026-08-19.
What is the latest version of Grafana?
The latest supported Grafana release is 13.1.0.
Is Grafana 12.3.8 still receiving security updates?
Yes — the 12.3 line is still supported until 2026-08-19 and receiving security updates. The latest release is 13.1.0.
Informational only, from public data (NVD · CISA KEV · EPSS · endoflife.date), and can lag or miss vendor-specific fixes. Always confirm against Grafana Labs's official advisory before you patch or upgrade — Grafana official site ↗