market · May 20, 2026
Grafana Labs Vulnerability Rollup Details GitHub Personal Access Token Compromise on May 17, 2026
Share the canonical public link.
A threat actor compromised a GitHub personal access token embedded in Grafana Labs’ GitHub Actions CI/CD workflow and exfiltrated the source code repository on or before May 17, 2026. The incident involved secrets management and CI/CD misconfiguration with no applicable CVE. Grafana Labs’ response included forensic investigation and security enhancements. Forward-looking risk includes adversary-held source code enabling discovery of undisclosed vulnerabilities or injection of tampered build artifacts. The breach was limited to Grafana Labs’ GitHub environment with no impact on customer production systems.