← Back

CVE-2026-28378

nvd nist
Published: Jul 7, 2026Modified: Jul 10, 2026

JSON object

Loading...
2.7
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Exploitability: 1.2 / Impact: 1.4
Source: NVD

Description

The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.

Affected (10)

Products: Grafana: Grafana
1 product
Grafana
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Grafana
From 11.6.0 to 11.6.13
From 12.1.0 to 12.1.9
From 12.2.0 to 12.2.7
From 12.3.0 to 12.3.5
From 11.6.0 to 11.6.13
From 12.1.0 to 12.1.9
From 12.2.0 to 12.2.7
From 12.3.0 to 12.3.5
Version 12.4.0
Version 12.4.0

References (1)

Timeline

No history available yet.