CVE-2026-33377
7.1
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Exploitability: 2.8 / Impact: 4.2
Source: security@grafana.com (Secondary)
Description
An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.
Affected (13)
Related CWEs
References (1)
Source: security@grafana.com
Vendor Advisory
Timeline
No history available yet.