CVE-2026-21721
EUVD-2026-482027.01.2026, 09:15
The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| grafana | grafana | 10.2.0 ≤ 𝑥 < 11.6.9 |
| grafana | grafana | 12.0.0 ≤ 𝑥 < 12.0.8 |
| grafana | grafana | 12.1.0 ≤ 𝑥 < 12.1.5 |
| grafana | grafana | 12.2.0 ≤ 𝑥 < 12.2.3 |
| grafana | grafana | 11.6.9 |
| grafana | grafana | 12.0.8 |
| grafana | grafana | 12.1.5 |
| grafana | grafana | 12.2.3 |
| grafana | grafana | 12.3.0 |
| grafana | grafana | 12.3.1 |
𝑥
= Vulnerable software versions
Red Hat Enterprise Linux Releases