CVE-2026-21724
published 2026-03-26CVE-2026-21724: A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify…
PriorityP423medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
0.24%
15.2th percentile
A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | grafana_grafana | >= 0 < 1.9.2-0.20260323180334-daffe750de85 | 1.9.2-0.20260323180334-daffe750de85 |
| grafana | grafana | >= 11.6.9 < 11.6.14 | 11.6.14 |
| grafana | grafana | >= 12.1.5 < 12.1.10 | 12.1.10 |
| grafana | grafana | >= 12.2.2 < 12.2.8 | 12.2.8 |
| grafana | grafana | >= 12.3.1 < 12.3.6 | 12.3.6 |
| grafana_labs | grafana | <= 13.2.0 | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
osv5.4MEDIUM
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Grafana OSS: Authorization bypass allows users with Editor role to modify protected webhook URLs without permissions
ghsa·2026-03-26
CVE-2026-21724 [MEDIUM] CWE-285 Grafana OSS: Authorization bypass allows users with Editor role to modify protected webhook URLs without permissions
Grafana OSS: Authorization bypass allows users with Editor role to modify protected webhook URLs without permissions
A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission.
A patched version is available at https://github.com/grafana/grafana/releases/tag/v12.3.6.
GHSA
GHSA-7g92-g4vh-hp84: A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role
ghsa_unreviewed·2026-03-26
CVE-2026-21724 [MEDIUM] CWE-285 GHSA-7g92-g4vh-hp84: A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role
A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission.
OSV
CVE-2026-21724: A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role
osv·2026-03-26·CVSS 5.4
CVE-2026-21724 [MEDIUM] CVE-2026-21724: A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role
A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission.
Red Hat
Grafana OSS: Grafana OSS: Authorization bypass allows modification of protected webhook URLs
vendor_redhat·2026-03-26·CVSS 5.4
CVE-2026-21724 [MEDIUM] CWE-266 Grafana OSS: Grafana OSS: Authorization bypass allows modification of protected webhook URLs
Grafana OSS: Grafana OSS: Authorization bypass allows modification of protected webhook URLs
A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission.
A flaw was found in Grafana OSS. An authorization bypass vulnerability in the provisioning contact points API allows users with an Editor role to modify protected webhook URLs. This can lead to unauthorized changes to notification configurations, potentially resulting in information disclosure or integrity issues.
Package: grafana (Red Hat Enterprise Linux 10) - Not affected
Package: grafana (Red Hat Enterprise Linux 8) - Not affected
P
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-21724 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-21724 [MEDIUM] CVE-2026-21724 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21724 :
Grafana vulnerability analysis and mitigation
A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write permission.
Source : NVD
## 5.4
Score
Published March 26, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Grafana
MinimOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:grafana:grafana
grafana-11.6
Sources
NVD
Chainguard No Fix Added at: Apr 02, 2026
MinimOS Severity MEDIUM Has
Bugzilla
CVE-2026-72585 grafana: Grafana: Authorization bypass allows Editor to delete protected contact points
bugzilla·2026-08-10·CVSS 4.3
CVE-2026-72585 [MEDIUM] CVE-2026-72585 grafana: Grafana: Authorization bypass allows Editor to delete protected contact points
CVE-2026-72585 grafana: Grafana: Authorization bypass allows Editor to delete protected contact points
An authorization bypass vulnerability in Grafana through 13.2.0 allows an Editor-role user to delete protected contact points (receivers) without the required alert.notifications.receivers.protected:write permission. The fix for CVE-2026-21724 addressed only the UPDATE code path in both pkg/services/ngalert/provisioning/contactpoints.go and pkg/services/ngalert/notifier/receiver_svc.go, but the DELETE path in both receiver services was not updated with the protected-field check, leaving deletion operations unguarded.
2026-03-26
Published