BIT-grafana-2026-33377

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/grafana/BIT-grafana-2026-33377.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-grafana-2026-33377
Aliases
  • CVE-2026-33377
Published
2026-05-15T08:42:45.411Z
Modified
2026-05-15T11:00:11.432520Z
Summary
Dashboard Import Overwrites ACL — Editor Privilege Escalation to Dashboard Admin
Details

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.

Database specific
{
    "cpes": [
        "cpe:2.3:a:grafana:grafana:*:*:*:*:*:go:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / grafana

Package

Name
grafana
Purl
pkg:bitnami/grafana

Severity

  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
8.5.0
Fixed
11.6.14
Introduced
12.0.0
Fixed
12.2.8
Introduced
12.3.0
Fixed
12.3.6
Introduced
12.4.0
Fixed
12.4.3
Introduced
13.0.0
Fixed
13.0.1

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/grafana/BIT-grafana-2026-33377.json"