CVE-2026-19197
6.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Summary
A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot's secret delete key using only its public share key (broken access control).
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Grafana | Grafana OSS | 12.4.0 < 12.4.8 | affected |
| Grafana | Grafana OSS | 13.0.0 < 13.0.6 | affected |
| Grafana | Grafana OSS | 13.1.0 < 13.1.3 | affected |
| Grafana | Grafana Enterprise | 12.4.0 < 12.4.8 | affected |
| Grafana | Grafana Enterprise | 13.0.0 < 13.0.6 | affected |
| Grafana | Grafana Enterprise | 13.1.0 < 13.1.3 | affected |
Weaknesses
- CWE-862: CWE-862
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.