CVE-2026-81841

Summary

Pausing a shared (public) dashboard did not revoke its access token for the endpoints that serve frontend bootstrap data. Anyone holding the link to a paused shared dashboard could still retrieve, without authenticating, the configuration of the dashboard's data sources, including stored credentials for data sources using browser access (missing authorization). Deleting the shared dashboard does revoke the token.

Affected Software

VendorProductVersion RangeStatus
GrafanaGrafana Enterprise11.6.0 <= 11.6.17affected
GrafanaGrafana Enterprise12.0.0 <= 12.0.10affected
GrafanaGrafana Enterprise12.1.0 <= 12.1.10affected
GrafanaGrafana Enterprise12.2.0 <= 12.2.11affected
GrafanaGrafana Enterprise12.3.0 <= 12.3.11affected
GrafanaGrafana Enterprise12.4.0 < 12.4.12affected
GrafanaGrafana Enterprise13.0.0 < 13.0.10affected
GrafanaGrafana Enterprise13.1.0 < 13.1.7affected
GrafanaGrafana Enterprise13.2.0 < 13.2.3affected
GrafanaGrafana OSS11.6.0 <= 11.6.17affected
GrafanaGrafana OSS12.0.0 <= 12.0.10affected
GrafanaGrafana OSS12.1.0 <= 12.1.10affected
GrafanaGrafana OSS12.2.0 <= 12.2.11affected
GrafanaGrafana OSS12.3.0 <= 12.3.11affected
GrafanaGrafana OSS12.4.0 < 12.4.12affected
GrafanaGrafana OSS13.0.0 < 13.0.10affected
GrafanaGrafana OSS13.1.0 < 13.1.7affected
GrafanaGrafana OSS13.2.0 < 13.2.3affected

Weaknesses

  • CWE-862: CWE-862

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References