CVE-2026-33377

EUVD-2026-30143
An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.1 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 13%
Affected Products (NVD)
VendorProductVersion
grafanagrafana
8.5.0 ≤
𝑥
< 11.6.14
grafanagrafana
12.2.0 ≤
𝑥
< 12.2.8
grafanagrafana
12.3.0 ≤
𝑥
< 12.3.6
grafanagrafana
12.4.0 ≤
𝑥
< 12.4.3
grafanagrafana
11.6.14
grafanagrafana
11.6.14:security01
grafanagrafana
12.2.8
grafanagrafana
12.2.8:security01
grafanagrafana
12.3.6
grafanagrafana
12.3.6:security01
grafanagrafana
12.4.3
grafanagrafana
13.0.0
grafanagrafana
13.0.1
𝑥
= Vulnerable software versions