CVE-2026-11817
published 2026-08-17CVE-2026-11817: This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted. In a…
PriorityP337medium5.3CVSS 4.0
AVNACLATNPRLUINVCLVINVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.26%
17.3th percentile
This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted. In a multi-organization stack, a user who is an Org Admin of a single organization can call GET /api/access-control/users/permissions/search?actionPrefix=dashboards: and receive permission data belonging to other organizations. The disclosed data is limited to dashboard and folder identifiers (UIDs) and per-user permission/scope mappings (which user holds which access on which dashboard). Dashboard contents, panels, query results, datasource credentials, secrets, and personal data are not exposed. This is a limited cross-organization information disclosure affecting multi-org deployments only.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| grafana | grafana_enterprise | 11.2.0 – 11.6.16 | — |
| grafana | grafana_enterprise | 12.2.0 – 12.2.10 | — |
| grafana | grafana_enterprise | 12.3.0 – 12.3.8 | — |
| grafana | grafana_enterprise | 12.4.0 – 12.4.5 | — |
| grafana | grafana_enterprise | 13.0.0 – 13.0.3 | — |
| grafana | grafana_enterprise | 13.1.0 – 13.1.0 | — |
| grafana | grafana_oss | 11.2.0 – 11.6.16 | — |
| grafana | grafana_oss | 12.2.0 – 12.2.10 | — |
| grafana | grafana_oss | 12.3.0 – 12.3.8 | — |
| grafana | grafana_oss | 12.4.0 – 12.4.5 | — |
| grafana | grafana_oss | 13.0.0 – 13.0.3 | — |
| grafana | grafana_oss | 13.1.0 – 13.1.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted.
ghsa_unreviewed·2026-08-18
CVE-2026-11817 [MEDIUM] CWE-863 This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted.
This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted. In a multi-organization stack, a user who is an Org Admin of a single organization can call GET /api/access-control/users/permissions/search?actionPrefix=dashboards: and receive permission data belonging to other organizations. The disclosed data is limited to dashboard and folder identifiers (UIDs) and per-user permission/scope mappings (which user holds which access on which dashboard). Dashboard contents, panels, query results, datasource credentials, secrets, and personal data are not exposed. This is a limited cross-organization information disclosure affecting multi-org deployments only.
VulDB
Grafana OSS/Enterprise search actionPrefix privileges management
vuldb·2026-08-17·CVSS 5.3
CVE-2026-11817 [MEDIUM] Grafana OSS/Enterprise search actionPrefix privileges management
A vulnerability labeled as problematic has been found in Grafana OSS and Enterprise. The impacted element is an unknown function of the file /api/access-control/users/permissions/search. The manipulation of the argument actionPrefix results in improper privilege management.
This vulnerability is cataloged as CVE-2026-11817. The attack may be launched remotely. There is no exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-17
Published