← Back

CVE-2026-21722

nvd nist
Published: Feb 12, 2026Modified: Feb 27, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: security@grafana.com (Secondary)

Description

Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange. This did not leak any annotations that would not otherwise be visible on the public dashboard.

Affected (8)

Products: Grafana: Grafana
1 product
Grafana
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Grafana
From 12.0.0 to 12.1.6
From 12.2.0 to 12.2.4
From 12.3.0 to 12.3.2
From 9.3.0 to 11.6.10
Version 11.6.10
Version 12.1.6
Version 12.2.4
Version 12.3.2

References (1)

Timeline

No history available yet.