CVE-2026-33377

EUVD-2026-30143
An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 11.86%
Affected Products (NVD)
VendorProductVersion
grafanagrafana
8.5.0 ≤
𝑥
< 11.6.14
grafanagrafana
12.2.0 ≤
𝑥
< 12.2.8
grafanagrafana
12.3.0 ≤
𝑥
< 12.3.6
grafanagrafana
12.4.0 ≤
𝑥
< 12.4.3
grafanagrafana
11.6.14
grafanagrafana
11.6.14:security01
grafanagrafana
12.2.8
grafanagrafana
12.2.8:security01
grafanagrafana
12.3.6
grafanagrafana
12.3.6:security01
grafanagrafana
12.4.3
grafanagrafana
13.0.0
grafanagrafana
13.0.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
grafana
jammy
dne
noble
dne
questing
dne
resolute
dne
xenial
needs-triage
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
grafana
RHEL 8
0:9.2.10-32.el8_10.1
fixed
RHEL 9
0:10.2.6-23.el9_8.2
fixed
grafana-selinux
RHEL 8
0:9.2.10-32.el8_10.1
fixed
RHEL 9
0:10.2.6-23.el9_8.2
fixed