CVE-2026-33377
published 2026-05-13CVE-2026-33377: An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate…
PriorityP338high7.1CVSS 3.1
AVNACLPRLUINSUCLIHAN
EPSS
0.23%
13.5th percentile
An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| grafana | grafana | — | — |
| grafana | grafana | — | — |
| grafana | grafana | — | — |
| grafana | grafana | — | — |
| grafana | grafana | — | — |
| grafana | grafana | — | — |
| grafana | grafana | — | — |
| grafana | grafana | >= 12.2.0 < 12.2.8 | 12.2.8 |
| grafana | grafana | >= 12.3.0 < 12.3.6 | 12.3.6 |
| grafana | grafana | >= 12.4.0 < 12.4.3 | 12.4.3 |
| grafana | grafana | >= 8.5.0 < 11.6.14 | 11.6.14 |
| grafana | grafana_oss | >= 11.6.14 < 11.6.14+security-04 | 11.6.14+security-04 |
| grafana | grafana_oss | 12.0.0 – 12.2.8 | — |
| grafana | grafana_oss | >= 12.2.8 < 12.2.8+security-04 | 12.2.8+security-04 |
| grafana | grafana_oss | 12.3.0 – 12.3.6 | — |
| grafana | grafana_oss | >= 12.3.6 < 12.3.6+security-04 | 12.3.6+security-04 |
| grafana | grafana_oss | 12.4.0 – 12.4.3 | — |
| grafana | grafana_oss | >= 12.4.3 < 12.4.3+security-02 | 12.4.3+security-02 |
| grafana | grafana_oss | 13.0.0 – 13.0.1 | — |
| grafana | grafana_oss | >= 13.0.1 < 13.0.1+security-01 | 13.0.1+security-01 |
| grafana | grafana_oss | 8.5.0 – 11.6.14 | — |
| multicluster-globalhub | multicluster-globalhub-grafana-rhel9 | — | — |
| rhacm2 | acm-grafana-rhel9 | — | — |
| rhceph | grafana-rhel10 | — | — |
| rhceph | grafana-rhel9 | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Grafana OSS up to 13.0.1+security-00 access control (WID-SEC-2026-1546)
vuldb·2026-05-16·CVSS 7.1
CVE-2026-33377 [HIGH] Grafana OSS up to 13.0.1+security-00 access control (WID-SEC-2026-1546)
A vulnerability was found in Grafana OSS and classified as critical. This impacts an unknown function. Executing a manipulation can lead to improper access controls.
The identification of this vulnerability is CVE-2026-33377. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
GHSA
GHSA-5cv7-h7gr-wjgh: An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard
ghsa_unreviewed·2026-05-13
CVE-2026-33377 [HIGH] CWE-284 GHSA-5cv7-h7gr-wjgh: An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard
An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.
Red Hat
grafana: Grafana: Privilege escalation via dashboard overwrite
vendor_redhat·2026-05-13·CVSS 7.1
CVE-2026-33377 [HIGH] CWE-267 grafana: Grafana: Privilege escalation via dashboard overwrite
grafana: Grafana: Privilege escalation via dashboard overwrite
An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.
A flaw was found in Grafana. A user with editor privileges can overwrite a dashboard not owned by them, leading to privilege escalation on that specific dashboard. This allows the editor to gain administrative control over the affected dashboard.
Statement: A privilege escalation flaw exists in Grafana, allowing an authenticated editor with write access to a dashboard to overwrite other dashboards not owned by them. This grants the editor administrative control over the targeted dashboard, potentially leading to unauthorized data manipulation or exposure wi
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-33377 grafana: Grafana: Privilege escalation via dashboard overwrite [fedora-all]
bugzilla·2026-07-16·CVSS 7.1
CVE-2026-33377 [HIGH] CVE-2026-33377 grafana: Grafana: Privilege escalation via dashboard overwrite [fedora-all]
CVE-2026-33377 grafana: Grafana: Privilege escalation via dashboard overwrite [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.
Bugzilla
CVE-2026-33377 grafana: Grafana: Privilege escalation via dashboard overwrite
bugzilla·2026-05-13·CVSS 7.1
CVE-2026-33377 [HIGH] CVE-2026-33377 grafana: Grafana: Privilege escalation via dashboard overwrite
CVE-2026-33377 grafana: Grafana: Privilege escalation via dashboard overwrite
An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.
2026-05-13
Published