3.1

CVE-2026-28378

Cross-Organization Public Dashboard Deletion via Missing Org Isolation

The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GrafanaGrafana SwEdition- Version >= 11.6.0 <= 11.6.13
GrafanaGrafana SwEditionenterprise Version >= 11.6.0 <= 11.6.13
GrafanaGrafana SwEdition- Version >= 12.1.0 <= 12.1.9
GrafanaGrafana SwEditionenterprise Version >= 12.1.0 <= 12.1.9
GrafanaGrafana SwEdition- Version >= 12.2.0 <= 12.2.7
GrafanaGrafana SwEditionenterprise Version >= 12.2.0 <= 12.2.7
GrafanaGrafana SwEdition- Version >= 12.3.0 <= 12.3.5
GrafanaGrafana SwEditionenterprise Version >= 12.3.0 <= 12.3.5
GrafanaGrafana Version12.4.0 SwEdition-
GrafanaGrafana Version12.4.0 SwEditionenterprise
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.034
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 2.7 1.2 1.4
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
security@grafana.com 3.1 1.6 1.4
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

https://grafana.com/security/security-advisories/cve-2026-28378
Broken Link