An authorization bypass in Grafana’s data source proxy API allows users to gain unauthorized access to data by inserting an additional slash (/) in the request path. This flaw affects endpoints in Alertmanager and certain Prometheus-based data sources that rely on path-specific permissions. The vulnerability impacts instances that are running Grafana >= 10.4.0