← Back

CVE-2026-21721

nvd nist
Published: Jan 27, 2026Modified: Apr 20, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.8 / Impact: 5.2
Source: security@grafana.com (Secondary)

Description

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.

Affected (10)

Products: Grafana: Grafana
1 product
Grafana
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Grafana
From 10.2.0 to 11.6.9
From 12.0.0 to 12.0.8
From 12.1.0 to 12.1.5
From 12.2.0 to 12.2.3
Version 11.6.9
Version 12.0.8
Version 12.1.5
Version 12.2.3
Version 12.3.0
Version 12.3.1

References (1)

Source: security@grafana.com
Vendor Advisory

Timeline

No history available yet.