CVE-2026-21721Incorrect Authorization in Grafana

Severity
8.1HIGHNVD
EPSS
0.0%
top 98.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 27

Description

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* action. As a result, a user who has permission management rights on one dashboard can read and modify permissions on other dashboards. This is an organization‑internal privilege escalation.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages2 packages

CVEListV5grafana/grafana_grafana12.3.012.3.1+4
CVEListV5grafana/grafana_grafana-enterprise10.2.011.6.9+4

🔴Vulnerability Details

3
CVEList
Dashboard Permissions Scope Bypass Enables Cross‑Dashboard Privilege Escalation2026-01-27
OSV
CVE-2026-21721: The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards2026-01-27
GHSA
GHSA-jgfq-mgxg-4qwm: The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards2026-01-27

📋Vendor Advisories

1
Red Hat
grafana/grafana/pkg/services/dashboards: Grafana Dashboard Permissions Scope Bypass Enables Cross‑Dashboard Privilege Escalation2026-01-27

🕵️Threat Intelligence

1
Wiz
CVE-2026-21721 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-21721 — Incorrect Authorization in Grafana | cvebase