CVE-2026-21721
EUVD-2026-482027.01.2026, 09:15
The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| grafana | grafana | 10.2.0 ≤ 𝑥 < 11.6.9 |
| grafana | grafana | 12.0.0 ≤ 𝑥 < 12.0.8 |
| grafana | grafana | 12.1.0 ≤ 𝑥 < 12.1.5 |
| grafana | grafana | 12.2.0 ≤ 𝑥 < 12.2.3 |
| grafana | grafana | 11.6.9 |
| grafana | grafana | 12.0.8 |
| grafana | grafana | 12.1.5 |
| grafana | grafana | 12.2.3 |
| grafana | grafana | 12.3.0 |
| grafana | grafana | 12.3.1 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | 0:10.2.6-22.el10_1 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | 0:10.2.6-20.el10_0 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9 | 0:10.2.6-18.el9_7 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | 0:10.2.6-17.el9_6 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2.11 | 1783578847 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2.12 | 1774002166 ≤ 𝑥 < * | ADP |
| Red Hat | Red Hat Advanced Cluster Management for Kubernetes 2.13 | 1774950654 ≤ 𝑥 < * | ADP |
Red Hat Enterprise Linux Releases
Common Weakness Enumeration
- CWE-863 - Incorrect AuthorizationThe software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
- CWE-639 - Authorization Bypass Through User-Controlled KeyThe system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
References