CVE-2026-13720

Summary

An Editor can set file-provisioning metadata (the grafana.app/managedBy, grafana.app/managerId and grafana.app/sourcePath annotations) when creating a dashboard through the dashboard API, because these fields were stored without an authorization check. The dashboard then appears file-provisioned, and administrators can no longer update or delete it through Grafana. The impact is limited to the same organization and no data is exposed.

Affected Software

VendorProductVersion RangeStatus
GrafanaGrafana OSS12.0.0 <= 12.0.10affected
GrafanaGrafana OSS12.1.0 <= 12.1.10affected
GrafanaGrafana OSS12.2.0 <= 12.2.11affected
GrafanaGrafana OSS12.3.0 <= 12.3.11affected
GrafanaGrafana OSS12.4.0 < 12.4.12affected
GrafanaGrafana OSS13.0.0 < 13.0.10affected
GrafanaGrafana OSS13.1.0 < 13.1.7affected
GrafanaGrafana OSS13.2.0 < 13.2.3affected
GrafanaGrafana Enterprise12.0.0 <= 12.0.10affected
GrafanaGrafana Enterprise12.1.0 <= 12.1.10affected
GrafanaGrafana Enterprise12.2.0 <= 12.2.11affected
GrafanaGrafana Enterprise12.3.0 <= 12.3.11affected
GrafanaGrafana Enterprise12.4.0 < 12.4.12affected
GrafanaGrafana Enterprise13.0.0 < 13.0.10affected
GrafanaGrafana Enterprise13.1.0 < 13.1.7affected
GrafanaGrafana Enterprise13.2.0 < 13.2.3affected

Weaknesses

  • CWE-285: CWE-285
  • CWE-915: CWE-915
  • CWE-345: CWE-345

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References