cbcvebase.
CVE-2026-28378
published 2026-07-07

CVE-2026-28378: The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging…

PriorityP410low2.7CVSS 3.1
AVNACLPRHUINSUCNILAN
EPSS
0.14%
3.5th percentile
The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.

Affected

15 ranges
VendorProductVersion rangeFixed in
grafanagrafana
grafanagrafana11.6.0 – 11.6.13
grafanagrafana12.1.0 – 12.1.9
grafanagrafana12.2.0 – 12.2.7
grafanagrafana12.3.0 – 12.3.5
grafanagrafana_enterprise11.6.0 – 11.6.13
grafanagrafana_enterprise12.1.0 – 12.1.9
grafanagrafana_enterprise12.2.0 – 12.2.7
grafanagrafana_enterprise12.3.0 – 12.3.5
grafanagrafana_enterprise12.4.0 – 12.4.1
grafanagrafana_oss11.6.0 – 11.6.13
grafanagrafana_oss12.1.0 – 12.1.9
grafanagrafana_oss12.2.0 – 12.2.7
grafanagrafana_oss12.3.0 – 12.3.5
grafanagrafana_oss12.4.0 – 12.4.1

CVSS provenance

nvdv3.12.7LOWCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
vendor_redhat2.7LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.