Grafana Databricks Datasource Plugin OAuth Passthrough Vulnerability Leading to Unauthorized Data Access

Vulnerability

A vulnerability exists in the Grafana Databricks Datasource Plugin versions 1.6.0 prior to 1.12.0, when OAuth passthrough is enabled. In scenarios where multiple users access the same datasource simultaneously on a single Grafana instance, the wrong user identifier may be used. This can result in unauthorized information being returned to users.

Impact

Exploitation of this vulnerability could lead to unauthorized access to information, allowing users to view data for which they do not have permission.

Remediation

Users can update to Grafana Databricks Datasource Plugin version 1.12.1 to address this vulnerability.

Added: Nov 11, 2025, 9:33 PM
Updated: Nov 11, 2025, 9:33 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
4.6
remediation
7.7
relevance
1.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.