BIT-grafana-2026-21722

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/grafana/BIT-grafana-2026-21722.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-grafana-2026-21722
Aliases
  • CVE-2026-21722
Published
2026-02-20T08:41:29.411Z
Modified
2026-02-20T09:15:17.815036Z
Summary
Public Dashboards time range restriction on annotations can be bypassed
Details

Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange.

This did not leak any annotations that would not otherwise be visible on the public dashboard.

Database specific
{
    "severity": "Medium",
    "cpes": [
        "cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*"
    ]
}
References

Affected packages

Bitnami / grafana

Package

Name
grafana
Purl
pkg:bitnami/grafana

Severity

  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
9.3.0
Fixed
11.6.10
Introduced
12.0.0
Fixed
12.1.6
Introduced
12.2.0
Fixed
12.2.4
Introduced
12.3.0
Fixed
12.3.2

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/grafana/BIT-grafana-2026-21722.json"