VDB

CVE-2026-63199

CVE-2026-63199 PUBLISHED CVSS 8.3 HIGH

Reported by GitHub_M · Published September 18, 2026

Perses is an open-source dashboard and visualization project for observability data. From 0.43.0 until 0.54.0-rc.0, the datasource creation and unsaved datasource proxy paths authorize the caller on a Datasource or GlobalDatasource scope but do not require read permission for the separately grantable associated project or global Secret before resolving it. A low-privilege user with GlobalDatasource:create or corresponding project datasource creation rights can attach a project or global Secret that the user cannot otherwise read, point the datasource at a service controlled by the user, and cause Perses to send the decrypted secret in plaintext, bypassing project and global scope separation. This issue is fixed in version 0.54.0-rc.0.

Risk Scores

CVSS 4.0
8.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

Affected Products

VendorProductVersions
persesperses>= 0.43.0, < 0.54.0-rc.0
github.comperses/perses0.43.0
persesperses>= 0.43.0, < 0.54.0-rc.0, >= 0.43.0, < 0.54.0-rc.0, >= 0.43.0, < 0.54.0-rc.0

Timeline

  • Jul 31, 2026 CVE Published
  • Sep 16, 2026 CVE Updated
  • Sep 19, 2026 EPSS Score
  • Sep 19, 2026 Security Advisory
  • Sep 24, 2026 EPSS Score
  • Sep 25, 2026 EPSS Score
  • Sep 27, 2026 EPSS Score
  • Sep 30, 2026 EPSS Score
  • Oct 3, 2026 EPSS Score
  • Oct 7, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›