CVE-2026-19197

Summary

A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot's secret delete key using only its public share key (broken access control).

Affected Software

VendorProductVersion RangeStatus
GrafanaGrafana OSS12.4.0 < 12.4.8affected
GrafanaGrafana OSS13.0.0 < 13.0.6affected
GrafanaGrafana OSS13.1.0 < 13.1.3affected
GrafanaGrafana Enterprise12.4.0 < 12.4.8affected
GrafanaGrafana Enterprise13.0.0 < 13.0.6affected
GrafanaGrafana Enterprise13.1.0 < 13.1.3affected

Weaknesses

  • CWE-862: CWE-862

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References