BIT-grafana-2026-21727

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/grafana/BIT-grafana-2026-21727.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-grafana-2026-21727
Aliases
Published
2026-04-21T12:04:43Z
Modified
2026-09-08T08:47:51Z
Summary
Grafana Correlations: Cross-Tenant Data Disclosure and Permanent Deletion via Legacy org_id=0 Record
Details

A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records. Due to a backward compatibility condition allowing org_id = 0 records to be returned across organizations, a user with datasource management privileges could read and permanently delete legacy correlation data belonging to another organization. This issue affects correlations created prior to Grafana 10.2 and is fixed in >=11.6.11, >=12.0.9, >=12.1.6, and >=12.2.4.

Thanks to Gyu-hyeok Lee (g2h) for reporting this vulnerability.

Database specific
{
    "cpes":  [
        "cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:*"
    ],
    "severity":  "Low"
}
References

Affected packages

Bitnami / grafana

Package

Name
grafana
Purl
pkg:bitnami/grafana

Severity

  • 3.3 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
11.6.11
Introduced
12.0.0
Fixed
12.0.9
Introduced
12.1.0
Fixed
12.1.6
Introduced
12.2.0
Fixed
12.2.4
Introduced
12.3.0
Fixed
12.3.3

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/grafana/BIT-grafana-2026-21727.json"