CVE-2026-28378
published 2026-07-07CVE-2026-28378: The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging…
PriorityP410low2.7CVSS 3.1
AVNACLPRHUINSUCNILAN
EPSS
0.14%
3.5th percentile
The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| grafana | grafana | — | — |
| grafana | grafana | 11.6.0 – 11.6.13 | — |
| grafana | grafana | 12.1.0 – 12.1.9 | — |
| grafana | grafana | 12.2.0 – 12.2.7 | — |
| grafana | grafana | 12.3.0 – 12.3.5 | — |
| grafana | grafana_enterprise | 11.6.0 – 11.6.13 | — |
| grafana | grafana_enterprise | 12.1.0 – 12.1.9 | — |
| grafana | grafana_enterprise | 12.2.0 – 12.2.7 | — |
| grafana | grafana_enterprise | 12.3.0 – 12.3.5 | — |
| grafana | grafana_enterprise | 12.4.0 – 12.4.1 | — |
| grafana | grafana_oss | 11.6.0 – 11.6.13 | — |
| grafana | grafana_oss | 12.1.0 – 12.1.9 | — |
| grafana | grafana_oss | 12.2.0 – 12.2.7 | — |
| grafana | grafana_oss | 12.3.0 – 12.3.5 | — |
| grafana | grafana_oss | 12.4.0 – 12.4.1 | — |
CVSS provenance
nvdv3.12.7LOWCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
vendor_redhat2.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying
ghsa_unreviewed·2026-07-08
CVE-2026-28378 [LOW] The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying
The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.
VulDB
Grafana up to 12.4.1 Public Dashboard Deletion Endpoint improper isolation or compartmentalization
vuldb·2026-07-07·CVSS 3.1
CVE-2026-28378 [LOW] Grafana up to 12.4.1 Public Dashboard Deletion Endpoint improper isolation or compartmentalization
A vulnerability categorized as problematic has been discovered in Grafana up to 11.6.13/12.1.9/12.2.7/12.3.5/12.4.1. Affected by this vulnerability is an unknown functionality of the component Public Dashboard Deletion Endpoint. Such manipulation leads to improper isolation or compartmentalization.
This vulnerability is documented as CVE-2026-28378. The attack can be executed remotely. There is not any exploit available.
Red Hat
grafana: Grafana: Unauthorized public dashboard deletion across organizations
vendor_redhat·2026-07-07·CVSS 2.7
CVE-2026-28378 [LOW] CWE-1220 grafana: Grafana: Unauthorized public dashboard deletion across organizations
grafana: Grafana: Unauthorized public dashboard deletion across organizations
The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.
A flaw in Grafana's public dashboard deletion endpoint lacks organization isolation, allowing an Organization Administrator to delete public dashboards in other organizations using the target dashboard's ID.
Statement: This Low impact flaw in Grafana allows an authenticated Organization Administrator to delete public dashboards belonging to other organizations. This is due to insufficient isolation enforcement in the public dashboard deletion endpoint, potentially affecting the
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-28378 grafana: Grafana: Unauthorized public dashboard deletion across organizations [fedora-all]
bugzilla·2026-07-20·CVSS 2.7
CVE-2026-28378 [LOW] CVE-2026-28378 grafana: Grafana: Unauthorized public dashboard deletion across organizations [fedora-all]
CVE-2026-28378 grafana: Grafana: Unauthorized public dashboard deletion across organizations [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.
Bugzilla
CVE-2026-28378 grafana: Grafana: Unauthorized public dashboard deletion across organizations
bugzilla·2026-07-07·CVSS 2.7
CVE-2026-28378 [LOW] CVE-2026-28378 grafana: Grafana: Unauthorized public dashboard deletion across organizations
CVE-2026-28378 grafana: Grafana: Unauthorized public dashboard deletion across organizations
The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.
2026-07-07
Published