CVE-2026-72585
EUVD-2026-5522110.08.2026, 11:17
An authorization bypass vulnerability in Grafana through 13.2.0 allows an Editor-role user to delete protected contact points (receivers) without the required alert.notifications.receivers.protected:write permission.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| grafana | grafana | 𝑥 ≤ 13.2.0 | CNA |
Common Weakness Enumeration